All verified exploits

CVE-2026-22732 Spring Security Headers Silently Dropped

Deterministic high Spring Boot Added cve-verified-cve-2026-22732

Detects Spring Security applications where OnCommittedResponseWrapper fails to track Content-Length set via setHeader/setIntHeader/addIntHeader, causing the HTTP response to commit before security headers (X-Frame-Options, X-Content-Type-Options, Cache-Control) are written. All browser-side protections are silently disabled.

Is your app exploitable through CVE-2026-22732?

Scan your domain free