CVE-2026-47887
N/A
N/A
Summary
A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Framework | 7.0.0 <= 7.0.8 | affected |
| Spring | Spring Framework | 6.2.0 <= 6.2.19 | affected |
| Spring | Spring Framework | 6.1.0 <= 6.1.28 | affected |
| Spring | Spring Framework | 6.0.0 <= 6.0.30 | affected |
| Spring | Spring Framework | 5.3.0 <= 5.3.49 | affected |
| Spring | Spring Framework | 0 <= 5.2.25.RELEASE | affected |
Weaknesses
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.