[High] CVE-2026-40988 – An application using spring-security-saml2-service-provider and the REDIRECT bin...
High CVE-2026-40988 An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates the compressed SAML payload into memory. Affected versions: Spring Security...