Sensitive cookie with improper SameSite attribute in Spring Framework - CVE-2026-47889
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass sameSite cookie restrictions.
The vulnerability exists due to improper cookie attribute handling in JettyCoreServerHttpResponse when serializing response cookies. A remote attacker can cause an application to issue cookies without the sameSite attribute to bypass sameSite cookie restrictions.
Only WebFlux applications running on the Jetty 12 Core reactive adapter are vulnerable.
Affected software
Library Support for Spring
How to mitigate CVE-2026-47889
Library Support for Spring - update to 3.5.19