Open redirect in Spring Authorization Server and Spring Security - CVE-2026-41008
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an arbitrary URL.
The vulnerability exists due to improper input validation in the authorization endpoint when processing authorization requests containing a request_uri parameter. A remote attacker can send a crafted authorization request with an invalid request_uri and an unvalidated redirect_uri to redirect users to an arbitrary URL.
User interaction is required to follow the crafted authorization flow.
Affected software
Spring Security
How to mitigate CVE-2026-41008
Spring Security - update to 7.0.6