Open redirect in Spring Security - CVE-2026-41706
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an attacker-controlled URL after login.
The vulnerability exists due to improper input validation in CookieRequestCache and CookieServerRequestCache when processing the REDIRECT_URI cookie for post-login redirection. A remote attacker can influence the value of the REDIRECT_URI cookie to redirect users to an attacker-controlled URL after login.
User interaction is required because the victim must successfully log in for the redirect to occur.