CVE-2026-47887
Received Received - Intake

Open Redirect in Spring Framework

Vulnerability report for CVE-2026-47887, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: VMware

Description

A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-27
AI Q&A
2026-08-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 12 associated CPEs
Vendor Product Version / Range
vmware spring_framework to 7.0.8 (inc)
vmware spring_framework to 6.2.19 (inc)
vmware spring_framework to 6.1.28 (inc)
vmware spring_framework to 6.0.30 (inc)
vmware spring_framework to 5.3.49 (inc)
vmware spring_framework to 5.2.26 (exc)
vmware spring_framework 7.0.0
vmware spring_framework 6.2.0
vmware spring_framework 6.1.0
vmware spring_framework 6.0.0
vmware spring_framework 5.3.0
vmware spring_framework 5.2.25

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a medium-severity open redirect vulnerability in Spring Framework's UrlFileNameViewController. It affects Spring MVC applications using this controller mapped with an end-of-path without a configured prefix. Attackers can manipulate URLs to redirect users to malicious websites.

Detection Guidance

To detect this vulnerability, check if your Spring MVC application uses UrlFileNameViewController with an end-of-path mapping and no configured prefix. Review application logs for suspicious redirect patterns or unusual URL requests targeting the affected controller.

Impact Analysis

Attackers could trick users into visiting malicious sites, potentially leading to phishing attacks, malware downloads, or credential theft. Users might unknowingly expose sensitive data or fall victim to social engineering.

Compliance Impact

This vulnerability could indirectly impact compliance with GDPR and HIPAA by enabling open redirect attacks. Such attacks may lead to phishing or unauthorized data access, which could violate data protection requirements under these regulations.

Mitigation Strategies

Upgrade to the fixed versions of Spring Framework: 7.0.9 (OSS), 7.0.8.1 (Enterprise), 6.2.20 (Enterprise), 6.1.29 (Enterprise), 6.0.31 (Enterprise), 5.3.50 (Enterprise), or 5.2.26 (Enterprise). No additional mitigation steps are required beyond upgrading.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-47887. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart