CVE-2026-47883
Received
Received - Intake
Open Redirect Vulnerability in Spring Framework
Vulnerability report for CVE-2026-47883, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-27
Last updated on: 2026-08-27
Assigner: VMware
Description
Description
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| spring_project | spring_framework | From 6.2.0 (inc) to 6.2.19 (inc) |
| spring_project | spring_framework | From 7.0.0 (inc) to 7.0.8 (inc) |
| spring | framework | From 7.0.0 (inc) to 7.0.8 (inc) |
| spring | framework | From 6.2.0 (inc) to 6.2.19 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |