CVE-2026-47883 PUBLISHED

Spring Framework Open Redirect in UrlHandlerFilter

Assigner: vmware
Reserved: 20.05.2026 Published: 27.08.2026 Updated: 27.08.2026

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

Product Status

Vendor Spring
Product Spring Framework
Versions Default: unaffected
  • affected from 7.0.0 to 7.0.8 (incl.)
  • affected from 6.2.0 to 6.2.19 (incl.)

References

Problem Types

  • CWE-601 URL Redirection to Untrusted Site ('Open Redirect') CWE

Impacts

  • UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux.