home.social

#springsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #springsecurity, aggregated by home.social.

fetched live
  1. [Перевод] Axelix выходит в общий доступ. Путь в тысячу миль начинается с первого шага

    От имени основной команды Axelix и всех, кто внёс вклад в сообщество, я хочу заявить: мы наконец это сделали. Axelix, наконец, выходит в GA (Generally Available — общедоступная версия)! Для тех, кто не знает - Axelix это продукт с открытым (Open Source) ядром, который позволяет выявлять распространённые проблемы, подводные камни и неэффективности в Java-приложениях. Ядро продукта лежит на GitHub - можете использовать, это бесплатно. В этом посте я хочу поделиться историей и мотивацией, стоящей за продуктом в целом. Надеюсь, вам будет интересно.

    habr.com/ru/companies/spring_a

    #java #springboot #springdata #springcloud #springsecurity #opensource

  2. [Перевод] Axelix выходит в общий доступ. Путь в тысячу миль начинается с первого шага

    От имени основной команды Axelix и всех, кто внёс вклад в сообщество, я хочу заявить: мы наконец это сделали. Axelix, наконец, выходит в GA (Generally Available — общедоступная версия)! Для тех, кто не знает - Axelix это продукт с открытым (Open Source) ядром, который позволяет выявлять распространённые проблемы, подводные камни и неэффективности в Java-приложениях. Ядро продукта лежит на GitHub - можете использовать, это бесплатно. В этом посте я хочу поделиться историей и мотивацией, стоящей за продуктом в целом. Надеюсь, вам будет интересно.

    habr.com/ru/companies/spring_a

    #java #springboot #springdata #springcloud #springsecurity #opensource

  3. [Перевод] Axelix выходит в общий доступ. Путь в тысячу миль начинается с первого шага

    От имени основной команды Axelix и всех, кто внёс вклад в сообщество, я хочу заявить: мы наконец это сделали. Axelix, наконец, выходит в GA (Generally Available — общедоступная версия)! Для тех, кто не знает - Axelix это продукт с открытым (Open Source) ядром, который позволяет выявлять распространённые проблемы, подводные камни и неэффективности в Java-приложениях. Ядро продукта лежит на GitHub - можете использовать, это бесплатно. В этом посте я хочу поделиться историей и мотивацией, стоящей за продуктом в целом. Надеюсь, вам будет интересно.

    habr.com/ru/companies/spring_a

    #java #springboot #springdata #springcloud #springsecurity #opensource

  4. CVE-2026-22752: CRITICAL auth bypass in Spring Authorization Server (CVSS 9.6). Low-priv attackers can fully compromise confidentiality & integrity. No patch or workaround — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #CVE202622752 #infosec

  5. CVE-2026-22752: CRITICAL auth bypass in Spring Authorization Server (CVSS 9.6). Low-priv attackers can fully compromise confidentiality & integrity. No patch or workaround — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #CVE202622752 #infosec

  6. CVE-2026-22752: CRITICAL auth bypass in Spring Authorization Server (CVSS 9.6). Low-priv attackers can fully compromise confidentiality & integrity. No patch or workaround — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #CVE202622752 #infosec

  7. CVE-2026-22752: CRITICAL auth bypass in Spring Authorization Server (CVSS 9.6). Low-priv attackers can fully compromise confidentiality & integrity. No patch or workaround — monitor vendor updates. radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #CVE202622752 #infosec

  8. 🔒 HIGH severity: Spring for GraphQL (v1.0.0 – 2.0.3) is affected by CVE-2026-41856 — improper access control can bypass security annotations, risking unauthorized access. Review your authorization logic ASAP. radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #GraphQL

  9. 🔒 HIGH severity: Spring for GraphQL (v1.0.0 – 2.0.3) is affected by CVE-2026-41856 — improper access control can bypass security annotations, risking unauthorized access. Review your authorization logic ASAP. radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #GraphQL

  10. 🔒 HIGH severity: Spring for GraphQL (v1.0.0 – 2.0.3) is affected by CVE-2026-41856 — improper access control can bypass security annotations, risking unauthorized access. Review your authorization logic ASAP. radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #GraphQL

  11. 🔒 HIGH severity: Spring for GraphQL (v1.0.0 – 2.0.3) is affected by CVE-2026-41856 — improper access control can bypass security annotations, risking unauthorized access. Review your authorization logic ASAP. radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #GraphQL

  12. SAP Patches Critical Flaws in Commerce Cloud and S/4HANA

    SAP has patched a critical vulnerability in its Commerce Cloud and S/4HANA systems, warning that hackers could exploit the flaw to upload malicious code and take control of the application. This security gap, caused by a misconfigured Spring Security setup, put sensitive data and system integrity at risk.

    osintsights.com/sap-patches-cr

    #SapCommerceCloud #Cve202634263 #CodeInjection #ServersideCodeExecution #SpringSecurity

  13. Check out what's new in the #Spring community 👉 bit.ly/3NMwcbY

    The third milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring AI and Spring AMQP; along with the second milestone releases of Spring Data and Spring for Apache Kafka.

    #Java #SpringBoot #SpringData #SpringSecurity #SpringAI #SpringVault #ApacheKafka

  14. Check out what's new in the #Spring community 👉 bit.ly/3NMwcbY

    The third milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring AI and Spring AMQP; along with the second milestone releases of Spring Data and Spring for Apache Kafka.

    #Java #SpringBoot #SpringData #SpringSecurity #SpringAI #SpringVault #ApacheKafka

  15. Check out what's new in the #Spring community 👉 bit.ly/3NMwcbY

    The third milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring AI and Spring AMQP; along with the second milestone releases of Spring Data and Spring for Apache Kafka.

    #Java #SpringBoot #SpringData #SpringSecurity #SpringAI #SpringVault #ApacheKafka

  16. Check out what's new in the #Spring community 👉 bit.ly/3NMwcbY

    The third milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring AI and Spring AMQP; along with the second milestone releases of Spring Data and Spring for Apache Kafka.

    #Java #SpringBoot #SpringData #SpringSecurity #SpringAI #SpringVault #ApacheKafka

  17. Check out what's new in the community 👉 bit.ly/3NMwcbY

    The third milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring AI and Spring AMQP; along with the second milestone releases of Spring Data and Spring for Apache Kafka.

  18. 🚨 CVE-2026-22732 (CRITICAL, CVSS 9.1): Spring Security 5.7.0 – 7.0.3 vulnerability lets HTTP headers go unwritten, risking CSP/HSTS bypass. No auth needed, remote exploit possible. Upgrade urgently & enforce headers via WAF/CDN! radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #CVE202622732

  19. 🚨 CVE-2026-22732 (CRITICAL, CVSS 9.1): Spring Security 5.7.0 – 7.0.3 vulnerability lets HTTP headers go unwritten, risking CSP/HSTS bypass. No auth needed, remote exploit possible. Upgrade urgently & enforce headers via WAF/CDN! radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #CVE202622732

  20. 🚨 CVE-2026-22732 (CRITICAL, CVSS 9.1): Spring Security 5.7.0 – 7.0.3 vulnerability lets HTTP headers go unwritten, risking CSP/HSTS bypass. No auth needed, remote exploit possible. Upgrade urgently & enforce headers via WAF/CDN! radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #CVE202622732

  21. 🚨 CVE-2026-22732 (CRITICAL, CVSS 9.1): Spring Security 5.7.0 – 7.0.3 vulnerability lets HTTP headers go unwritten, risking CSP/HSTS bypass. No auth needed, remote exploit possible. Upgrade urgently & enforce headers via WAF/CDN! radar.offseq.com/threat/cve-20 #OffSeq #SpringSecurity #CVE202622732

  22. Check out what's new in the #Spring community 👉 bit.ly/4kZSJyw

    The second milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring Modulith and Spring AMQP; along with the first milestone releases of Spring Session, Spring for Apache Kafka and Spring LDAP.

    #Java #SpringBoot #SpringData #SpringSecurity #SpringAMQP #ApacheKafka

  23. Check out what's new in the #Spring community 👉 bit.ly/4kZSJyw

    The second milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring Modulith and Spring AMQP; along with the first milestone releases of Spring Session, Spring for Apache Kafka and Spring LDAP.

    #Java #SpringBoot #SpringData #SpringSecurity #SpringAMQP #ApacheKafka

  24. Check out what's new in the #Spring community 👉 bit.ly/4kZSJyw

    The second milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring Modulith and Spring AMQP; along with the first milestone releases of Spring Session, Spring for Apache Kafka and Spring LDAP.

    #Java #SpringBoot #SpringData #SpringSecurity #SpringAMQP #ApacheKafka

  25. Check out what's new in the #Spring community 👉 bit.ly/4kZSJyw

    The second milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring Modulith and Spring AMQP; along with the first milestone releases of Spring Session, Spring for Apache Kafka and Spring LDAP.

    #Java #SpringBoot #SpringData #SpringSecurity #SpringAMQP #ApacheKafka

  26. Check out what's new in the community 👉 bit.ly/4kZSJyw

    The second milestone releases of: Spring Boot, Spring Security, Spring Integration, Spring Modulith and Spring AMQP; along with the first milestone releases of Spring Session, Spring for Apache Kafka and Spring LDAP.

  27. Ever wondered if you're handling passwords securely in Java? 🤔 I switched to char[] instead of String — it’s mutable, log-safe, and I can wipe it from memory after use. But here's the kicker: Spring Security still expects String in many places. 🔄

    Is it worth using char[] despite the framework limits? What’s your go-to strategy for securing passwords in memory?

    Full breakdown on my blog: manueltechlabs.com/posts/why-i
    #Java #SpringSecurity #Cybersecurity #DevCommunity

  28. Ever wondered if you're handling passwords securely in Java? 🤔 I switched to char[] instead of String — it’s mutable, log-safe, and I can wipe it from memory after use. But here's the kicker: Spring Security still expects String in many places. 🔄

    Is it worth using char[] despite the framework limits? What’s your go-to strategy for securing passwords in memory?

    Full breakdown on my blog: manueltechlabs.com/posts/why-i
    #Java #SpringSecurity #Cybersecurity #DevCommunity

  29. This #InfoQ article explores a solution for Registering & Authenticating users through a client-side JavaScript application using the #SpringSecurity infrastructure, access and refresh tokens.

    🎯 The goal is to explain the process in greater detail through clear and easy-to-follow #FlowDiagrams.

    👉 Read it here: bit.ly/3DWoKFX

    #Java #Spring #InfoQ

  30. This #InfoQ article explores a solution for Registering & Authenticating users through a client-side JavaScript application using the #SpringSecurity infrastructure, access and refresh tokens.

    🎯 The goal is to explain the process in greater detail through clear and easy-to-follow #FlowDiagrams.

    👉 Read it here: bit.ly/3DWoKFX

    #Java #Spring #InfoQ

  31. This #InfoQ article explores a solution for Registering & Authenticating users through a client-side JavaScript application using the #SpringSecurity infrastructure, access and refresh tokens.

    🎯 The goal is to explain the process in greater detail through clear and easy-to-follow #FlowDiagrams.

    👉 Read it here: bit.ly/3DWoKFX

    #Java #Spring #InfoQ

  32. This #InfoQ article explores a solution for Registering & Authenticating users through a client-side JavaScript application using the #SpringSecurity infrastructure, access and refresh tokens.

    🎯 The goal is to explain the process in greater detail through clear and easy-to-follow #FlowDiagrams.

    👉 Read it here: bit.ly/3DWoKFX

    #Java #Spring #InfoQ

  33. This article explores a solution for Registering & Authenticating users through a client-side JavaScript application using the infrastructure, access and refresh tokens.

    🎯 The goal is to explain the process in greater detail through clear and easy-to-follow .

    👉 Read it here: bit.ly/3DWoKFX

  34. 🔍 Explore the best of #Java in 2025!

    We’ve handpicked our favorite #InfoQ articles to help you master the trends that defined last year and are already shaping 2026. These are the must-reads for every JVM developer:

    ➡️ Building a RAG Application with Spring Boot, Spring AI, MongoDB Atlas Vector Search, and OpenAI by Matteo Rossi
    bit.ly/47KRUUX

    ➡️ Spring Security Configuration with Flow Diagrams by Alexandr Manunin
    bit.ly/3DWoKFX

    ➡️ Infusing AI into Your Java applications by Don Bourne, Michal Broz, Laura Cowen, Daniel Oh, Kevin Dubois
    bit.ly/4oNmLqH

    ➡️ Spring AI 1.0 Delivers Easy AI Systems and Services by Josh Long
    bit.ly/4lTYBc3

    ➡️ Jakarta EE 11 Overview: Virtual Threads, Records, and the Future of Persistence by Otavio Santana
    bit.ly/46Pj4tX

    Stay informed. Stay inspired. And always #StayAhead of the curve! Knowledge is power! 💪

    #SpringAI #SpringSecurity #AI #RAG #JakartaEE #SoftwareEngineering

  35. 🔍 Explore the best of #Java in 2025!

    We’ve handpicked our favorite #InfoQ articles to help you master the trends that defined last year and are already shaping 2026. These are the must-reads for every JVM developer:

    ➡️ Building a RAG Application with Spring Boot, Spring AI, MongoDB Atlas Vector Search, and OpenAI by Matteo Rossi
    bit.ly/47KRUUX

    ➡️ Spring Security Configuration with Flow Diagrams by Alexandr Manunin
    bit.ly/3DWoKFX

    ➡️ Infusing AI into Your Java applications by Don Bourne, Michal Broz, Laura Cowen, Daniel Oh, Kevin Dubois
    bit.ly/4oNmLqH

    ➡️ Spring AI 1.0 Delivers Easy AI Systems and Services by Josh Long
    bit.ly/4lTYBc3

    ➡️ Jakarta EE 11 Overview: Virtual Threads, Records, and the Future of Persistence by Otavio Santana
    bit.ly/46Pj4tX

    Stay informed. Stay inspired. And always #StayAhead of the curve! Knowledge is power! 💪

    #SpringAI #SpringSecurity #AI #RAG #JakartaEE #SoftwareEngineering

  36. 🔍 Explore the best of #Java in 2025!

    We’ve handpicked our favorite #InfoQ articles to help you master the trends that defined last year and are already shaping 2026. These are the must-reads for every JVM developer:

    ➡️ Building a RAG Application with Spring Boot, Spring AI, MongoDB Atlas Vector Search, and OpenAI by Matteo Rossi
    bit.ly/47KRUUX

    ➡️ Spring Security Configuration with Flow Diagrams by Alexandr Manunin
    bit.ly/3DWoKFX

    ➡️ Infusing AI into Your Java applications by Don Bourne, Michal Broz, Laura Cowen, Daniel Oh, Kevin Dubois
    bit.ly/4oNmLqH

    ➡️ Spring AI 1.0 Delivers Easy AI Systems and Services by Josh Long
    bit.ly/4lTYBc3

    ➡️ Jakarta EE 11 Overview: Virtual Threads, Records, and the Future of Persistence by Otavio Santana
    bit.ly/46Pj4tX

    Stay informed. Stay inspired. And always #StayAhead of the curve! Knowledge is power! 💪

    #SpringAI #SpringSecurity #AI #RAG #JakartaEE #SoftwareEngineering

  37. 🔍 Explore the best of #Java in 2025!

    We’ve handpicked our favorite #InfoQ articles to help you master the trends that defined last year and are already shaping 2026. These are the must-reads for every JVM developer:

    ➡️ Building a RAG Application with Spring Boot, Spring AI, MongoDB Atlas Vector Search, and OpenAI by Matteo Rossi
    bit.ly/47KRUUX

    ➡️ Spring Security Configuration with Flow Diagrams by Alexandr Manunin
    bit.ly/3DWoKFX

    ➡️ Infusing AI into Your Java applications by Don Bourne, Michal Broz, Laura Cowen, Daniel Oh, Kevin Dubois
    bit.ly/4oNmLqH

    ➡️ Spring AI 1.0 Delivers Easy AI Systems and Services by Josh Long
    bit.ly/4lTYBc3

    ➡️ Jakarta EE 11 Overview: Virtual Threads, Records, and the Future of Persistence by Otavio Santana
    bit.ly/46Pj4tX

    Stay informed. Stay inspired. And always #StayAhead of the curve! Knowledge is power! 💪

    #SpringAI #SpringSecurity #AI #RAG #JakartaEE #SoftwareEngineering

  38. 🔍 Explore the best of in 2025!

    We’ve handpicked our favorite articles to help you master the trends that defined last year and are already shaping 2026. These are the must-reads for every JVM developer:

    ➡️ Building a RAG Application with Spring Boot, Spring AI, MongoDB Atlas Vector Search, and OpenAI by Matteo Rossi
    bit.ly/47KRUUX

    ➡️ Spring Security Configuration with Flow Diagrams by Alexandr Manunin
    bit.ly/3DWoKFX

    ➡️ Infusing AI into Your Java applications by Don Bourne, Michal Broz, Laura Cowen, Daniel Oh, Kevin Dubois
    bit.ly/4oNmLqH

    ➡️ Spring AI 1.0 Delivers Easy AI Systems and Services by Josh Long
    bit.ly/4lTYBc3

    ➡️ Jakarta EE 11 Overview: Virtual Threads, Records, and the Future of Persistence by Otavio Santana
    bit.ly/46Pj4tX

    Stay informed. Stay inspired. And always of the curve! Knowledge is power! 💪

  39. There is also #SpringSecurity integration and #Actuator integration examples on the website. Really interested to hear feedback from #Spring developers.