Open redirect in Spring Framework - CVE-2026-47887
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an arbitrary URL.
The vulnerability exists due to an open redirect in UrlFileNameViewController when processing requests in applications where it is mapped with an end-of-path and no prefix is configured. A remote attacker can send a specially crafted request to redirect users to an arbitrary URL.
Affected software
Library Support for Spring
How to mitigate CVE-2026-47887
Library Support for Spring - update to 3.5.19