THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-59316 (HIGH 8.2) — Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unen

[NVD] CVE-2026-59316 (HIGH 8.2) — Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unen

mednvdPublished 2026-08-27

CVE-2026-59316 CVSS: 8.2 HIGH Published: 2026-08-27T20:17:57.667

Spring Authorization Server's default consent page renders user-controlled values without HTML entity encoding. When using the DefaultConsentPage, an attacker can craft an OAuth2 authorization request containing a malicious value that is stored server-side and later rendered unencoded in the default consent page presented to the end

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-59316