CVE-2026-47883
Last modified
CVE-2026-47883 is a medium-severity vulnerability rated 6.1/10 on the CVSS scale. UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19. EPSS estimates a 0.19% chance of exploitation in the next 30 days.
Description
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Spring Framework | >= 6.2.0, < 6.2.20 |
| Vmware | Spring Framework | >= 7.0.0, < 7.0.8.1 |
References
- https://spring.io/security/cve-2026-47883Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-47883?
How severe is CVE-2026-47883?
How do I fix CVE-2026-47883?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-47878DefaultExecutionContextSerializer, used by default in Spring…7.3
- CVE-2026-47879Spring Cloud Gateway JsonToGrpcGatewayFilterFactory allows a…8.7
- CVE-2026-4788IBM Tivoli Netcool Impact 7.1.0.0 through 7.1.0.37 stores se…5.5
- CVE-2026-47880A producer who can publish to a JMS destination consumed by …5.4
- CVE-2026-47881Spring Batch's FlatFileItemReader supports files where a sin…7.5
- CVE-2026-47882When enabling Spring Boot DevTools support for a remote appl…8.3
- CVE-2026-47884Use of XsltView in a Spring MVC application can result in SS…9.8
- CVE-2026-47885The PartEventHttpMessageReader in Spring WebFlux does not en…7.5
- CVE-2026-47886Applications that evaluate user-supplied Spring Expression L…7.5
- CVE-2026-47887A Spring MVC application that uses UrlFileNameViewController…6.1
- CVE-2026-47888A Spring RSocket application is exposed to a memory leak via…7.5
- CVE-2026-47889A WebFlux application running on the Jetty 12 Core reactive …7.5
Are you affected by CVE-2026-47883?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
