SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-59355

MEDIUM · CVSS 6.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Versions 1.5.0 to 1.5.7 of Spring Authorization Server are vulnerable due to inadequate validation of the request_uri parameter at the authorization endpoint. This flaw allows attackers to exploit the system by crafting requests that redirect users to malicious sites, potentially leading to phishing attacks or other security breaches. Organizations using these versions should prioritize patching to mitigate the risk of open redirects and protect user data.

CVE
CVE-2026-59355
Severity
MEDIUM
CVSS
6.1
EPSS
0.23%

Original NVD Description

In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an attacker-controlled site.

Related CVEs

Other vulnerabilities affecting the same vendor(s)