-
Notifications
You must be signed in to change notification settings - Fork 1.4k
Open
Labels
type: dependency-upgradeA dependency upgradeA dependency upgrade
Description
spring-authorization-server v1.5.2 depends on com.nimbusds:nimbus-jose-jwt v9.47, which is vulnerable to CVE-2025-53864 (uncontrolled recursion -> DoS).
Sources :
The nimbus-jose-jwt project backported the gson upgrade in version 9.37.4 and this new release was bumped into spring security bom. Unfortunately, Spring Authorization Server don't use the release from Spring Security Bom.
How to fix this CVE in my project using latest release ?
- Should I request the nimbus-jose-jwt project to backport the fix also in v9.47 ?
- Is forcing the downgrade to v9.37.4 possible ?
- Any other idea ?
Thank you
Metadata
Metadata
Assignees
Labels
type: dependency-upgradeA dependency upgradeA dependency upgrade