Open redirect in Spring Framework - CVE-2026-47883
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an arbitrary URL.
The vulnerability exists due to an open redirect in UrlHandlerFilter when processing requests with very broadly matching patterns. A remote attacker can craft a request that triggers a redirect to an arbitrary URL to redirect users to an arbitrary URL.
The issue applies to the filter variants in both Spring MVC and Spring WebFlux.
Affected software
Library Support for Spring
How to mitigate CVE-2026-47883
Library Support for Spring - update to 3.5.19