SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-47883

MEDIUM · CVSS 6.1 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The UrlHandlerFilter in Spring Framework versions 6.2.0 to 7.0.8 is susceptible to an open redirect vulnerability when configured with overly broad matching patterns. This flaw could potentially allow attackers to redirect users to malicious sites, compromising user trust and security. Organizations using these versions of Spring MVC or Spring WebFlux should prioritize addressing this vulnerability to mitigate risks associated with unauthorized redirects.

CVE
CVE-2026-47883
Severity
MEDIUM
CVSS
6.1
EPSS
0.19%

Original NVD Description

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

Related CVEs

Other vulnerabilities affecting the same vendor(s)