Generated remediation guidance and an executive summary. No account required.
Spring Security versions 5.2.x prior to 5.2.4 and 5.3.x prior to 5.3.2 contain a signature wrapping vulnerability during SAML response validation. When using the spring-security-saml2-service-provider component, a malicious user can carefully modify an otherwise valid SAML response and append an arbitrary assertion that Spring Security will accept as valid.
Use CWE-347, Pivotal Software vendor hub and Spring Security product page to widen CVE-2020-5407 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-22112, CVE-2018-1258 and CVE-2020-5408 for nearby disclosures in the same product family. Additional editorial context is available in Cybersecurity Weekly Roundup: April 27, 2026 — Critical Zero-Days and Framework Failures.