CVE-2026-47889
N/A
N/A
Summary
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Framework | 7.0.0 <= 7.0.8 | affected |
| Spring | Spring Framework | 6.2.0 <= 6.2.19 | affected |
Weaknesses
- CWE-1275 Sensitive Cookie with Improper SameSite Attribute
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.