CVE-2018-1260

Spring Security OAuth RCE: stopped at runtime

Waratek RASP already blocks this exploit at runtime, inside the JVM - with no application change, no vendor patch, and no downtime.

Published May 11, 2018 · Updated March 4, 2026

Mitigated by Waratek CRITICAL CVSS 9.8 v3.0

The vulnerability

Remote code execution via crafted OAuth authorization request

Spring Security OAuth evaluates part of the authorization request as a Spring Expression Language (SpEL) expression when the resource owner is redirected to the approval endpoint. An attacker who crafts a malicious authorization request can smuggle a SpEL payload through that flow and have it evaluated by the server, achieving unauthenticated remote code execution against any application built on the vulnerable OAuth2 authorization server.

Affected softwareSpring Security OAuth
Affected versions2.0 before 2.0.15, 2.1 before 2.1.2, 2.2 before 2.2.2, and 2.3 before 2.3.3
WeaknessCode injection (unsafe SpEL evaluation) (CWE-94)
Published2018-05-11
SeverityCRITICAL · CVSS 9.8

Running an affected version? We can help.

Waratek RASP shields the vulnerable code in production - the exploit is blocked at runtime with no library upgrade, no redeploy, and no downtime. We can have you covered fast.

Talk to us about protection

How Waratek RASP stops it

Blocked at runtime by Waratek RASP

Waratek RASP ships a patch rule that blocks exploitation at the exact point the dangerous operation is attempted, inside the JVM.

Runtime, not perimeter

Waratek RASP acts inside the JVM at the exact call that turns input into code, so obfuscated and encoded payloads are caught where a WAF misses them.

No code changes

Protection is applied as a rule at runtime. No source edits, no recompilation, no library upgrade, and no application restart required.

Zero false positives

Rules target the specific unsafe behaviour of the exploit, so legitimate traffic keeps flowing while the attack is blocked and logged.

Flip one toggle in the Waratek Portal. The protection deploys to every attached application, with no restart.

Common questions

Spring Security OAuth RCE FAQ

Is Spring Security OAuth RCE (CVE-2018-1260) exploitable?

CVE-2018-1260 carries a CVSS 9.8/10 (CRITICAL) rating and affects Spring Security OAuth 2.0 before 2.0.15, 2.1 before 2.1.2, 2.2 before 2.2.2, and 2.3 before 2.3.3. Spring Security OAuth evaluates part of the authorization request as a Spring Expression Language (SpEL) expression when the resource owner is redirected to the approval endpoint. An attacker who crafts a malicious authorization request can smuggle a SpEL payload through that flow and have it evaluated by the server, achieving unauthenticated remote code execution against any application built on the vulnerable OAuth2 authorization server.

How does Waratek mitigate Spring Security OAuth RCE (CVE-2018-1260)?

Waratek RASP blocks exploitation of Spring Security OAuth RCE (CVE-2018-1260) inside the JVM at runtime, with no application code changes, no vendor patch and no restart.

Protect your apps in production

Get protected against Spring Security OAuth RCE - without code changes or redeploying

Book a call and we’ll show you how Waratek RASP shields your running applications against CVE-2018-1260 and attacks like it, and get you covered in production.