← Back to CVE search

CVE-2026-47883

Spring Framework

Description

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

CVSS 6.1EPSS 0.187%Risk 0.62
View source
Published
2026-08-27 06:17:18
Affected versions
<7.0.9
Type
Library
Last modified
2026-08-27 17:18:35
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N