CVE-2026-47883

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
References
Link Resource
https://spring.io/security/cve-2026-47883 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_framework:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-08-27 06:17

Updated : 2026-09-10 14:54


NVD link : CVE-2026-47883

Mitre link : CVE-2026-47883

CVE.ORG link : CVE-2026-47883


JSON object : View

Products Affected

vmware

  • spring_framework
CWE
CWE-601

URL Redirection to Untrusted Site ('Open Redirect')