Skip to main content
Spring Security

Spring Security

Search complete. 21 mentions across 5 episodes found for "Spring Security".

Sep 10, 2026

Josh LongHOST
0:24
I'm doing a two-part talk.
Josh LongHOST
0:26
It's two talks stitched together, one right after the other, with the legendary, inimitable, amazing, and also influential Rob Winch, lead of Spring Security.
Josh LongHOST
0:35
And it's going to be a spring security palooza.
Josh LongHOST
0:36
It's going to be amazing.
Josh LongHOST
0:37
So I'm hoping, up against all hope, that it's going to be recorded.
Felipe GutierrezGUEST
41:24
Thanks to the security, now I can do like a two-factor authentication, right? So easy that it's a feature that...
Felipe GutierrezGUEST
41:35
I think it was already also due right from previous versions of the Spring Security.
Felipe GutierrezGUEST
41:40
We needed to have that.
Felipe GutierrezGUEST
41:42
There was some implementations, of course, but now using this is so simple.
Josh LongHOST
3:11
I built a, a CLI with Spring Shell and device code flow and, uh, the Spring Auth Server.
Josh LongHOST
3:16
I built a web service and a React app, and I secured all that, uh, with the, uh, with the u- you know, Spring Security OAuth support and of course the Spring Auth Server.
Josh LongHOST
3:26
So really just about every use case, every place I can imagine.
Josh LongHOST
3:28
Messaging, gRPC, Kafka, integration, um, you know, um, web apps, uh, you know, everything.
Josh LongHOST
3:49
The Spring Auth Server is a incredibly capable OAuth IDP.
Josh LongHOST
3:54
And so imagine my delirium, my joy at, uh, the discovery that I could get today's guest, my friend Joe Grandia.
Josh LongHOST
4:02
He is the lead of the Spring Auth Server, which is itself part of the Spring Security project.
Josh LongHOST
4:08
So it's, um, you know, it...
James AzarHOST
7:15
26.4.15-1. and red hat bk 26.6 operator bundle 26.6.6-1 upgrade immediately if you can't patch today there's a real stop gap here in the admin council so go to realm settings login and disable forgot password across all your realms until you can patch this one up key cloak sits in front of everything else in your environment so an identity provider is exactly the system you don't want to discover was vulnerable after the fact so treat it as such all right The third up is a less single bug and more of a stack of them.
James AzarHOST
7:53
Spring's latest security update is patching 91 vulnerabilities across Spring Security, Spring AI, Cloud Config, DataRest, Integration, Reactor, Core Reactor, Netty, AAMQP, and Patch.
James AzarHOST
8:09
Patch would it be? Sorry, not a P.
James AzarHOST
8:13
uh all right one is rated critical over a dozen more are high severity and together these components sit inside more than 200 000 pieces of downstream software so if your organization runs java there's a good chance spring is already in your stack whether your team put it there directly or not the critical cve of the bunch is 2026.59 or 270 it hits springs security embedded unbound id ldap server and could let an attacker authenticate and even modify entries in that in-memory directory also worth flagging even though it's not in the top rated cve And this specific batch is CVE-2026-59-285, which is a critical remote code execution flaw in Spring for GraphQL and CVE-2026-59-318, a medium severity prompt injection privilege escalation in Spring's AI tool calling functionality, a preview of the bug class we're going to see a lot more of as AI tooling gets wired into application frameworks.
James AzarHOST
9:16
Spring has a real exploitation track record Spring for Shell wasn't that long ago, and CISA's catalog already lists several spring CVEs from prior year.
James AzarHOST
9:27
Worth noting, by the way, this vendor patched over 200 spring vulnerabilities in 2026 alone, compared to just 16 in 2025, largely from AI-assisted vulnerability hunting, on their end so expect the space to continue inventory where spring lives in your stack and prioritize patching today especially anywhere spring security or spring for graphql is exposed there as well Alright, we'll get to our fourth story, which is a breach at a security vendor, and security vendors are not exempt from it.
James AzarHOST
10:05
They're always a target, but it's worth walking through this one because the defense actually worked.
James AzarHOST
10:11
ReliaQuest, if you were at Hacker Summer Camp, you may have seen that name everywhere.
Jerry BellHOST
1:20
5.
Jerry BellHOST
1:20
Spring Security's embedded unbound ID LDAP server has a critical flaw that can hand a remote attacker admin access to an exposed in-memory directory.
Jerry BellHOST
1:30
Check the advisory for the fixed version, and since that in-memory LDAP is meant for testing, make sure it isn't reachable in production.
Jerry BellHOST
1:37
6.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.