Skip to main content

New: Meet Apex, the agent that runs your security program while you sleep

Blog

The Cantina blog

Research, perspectives, and field notes on where security is heading.

The Loop

Authorization Bypass in Spring Security 7: XML <intercept-url> Drops servlet-path When Building Path Matchers

Spring Security 7.0.0–7.0.4 silently discards the servlet-path attribute in XML authorization rules, enabling unauthenticated access to protected endpoints.

· Cantina

Spring Security Authorization Bypass CVE-2026-22754

Page 3 of 25 · 294 posts