PatchSiren cyber security CVE debrief
CVE-2026-47883 Spring CVE debrief
CVE-2026-47883 debrief based on CVE Program and NVD records. The vulnerability affects Spring Framework's UrlHandlerFilter, allowing open redirects when configured with broadly matching patterns. This issue impacts both Spring MVC and Spring WebFlux filter variants in versions 6.2.0-6.2.19 and 7.0.0-7.0.8. Defenders and security teams should assess exposure and prioritize remediation or compensating controls for affected versions. The CVE record and NVD vulnerability detail page provide information on the open redirect vulnerability.
- Vendor
- Spring
- Product
- Spring Framework
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-27
- Original CVE updated
- 2026-09-10
- Advisory published
- 2026-08-27
- Advisory updated
- 2026-09-10
Who should care
Defenders and security teams responsible for Spring Framework deployments should assess exposure and prioritize remediation or compensating controls for affected versions. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified, and checking relevant monitoring, detection, and logs for exposed assets that need extra review.
Why it matters
CVE-2026-47883 is a medium-severity vulnerability in Spring Framework's UrlHandlerFilter, allowing open redirects when configured with broadly matching patterns. Defenders and security teams should assess exposure, prioritize remediation or compensating controls for affected versions 6.2.0-6.2.19 and 7.0.0-7.0.8, and verify vendor-provided patches or updates to prevent potential open redirect attacks.
- Potential open redirect attacks may lead to phishing or other malicious activities
- Exposure of sensitive data or systems may occur if not properly mitigated
- Verification of vendor-provided patches or updates is necessary to prevent exploitation
- Remediation priority is medium due to the CVSS score of 6.1
Technical summary
The UrlHandlerFilter in Spring Framework is vulnerable to an open redirect when configured with very broadly matching patterns. This issue affects both Spring MVC and Spring WebFlux filter variants in versions 6.2.0-6.2.19 and 7.0.0-7.0.8. The vulnerability has a medium severity with a CVSS score of 6.1. Defenders and security teams should assess exposure and prioritize remediation or compensating controls for affected versions. The CVE record and NVD vulnerability detail page provide information on the open redirect vulnerability.
Defensive priority
Assess exposure and prioritize remediation for Spring Framework versions 6.2.0-6.2.19 and 7.0.0-7.0.8
Recommended defensive actions
- Assess exposure of Spring Framework versions 6.2.0-6.2.19 and 7.0.0-7.0.8 in your environment
- Prioritize remediation or apply compensating controls for affected versions
- Verify vendor-provided patches or updates for Spring Framework
- Monitor for potential open redirect attacks
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record and NVD vulnerability detail page provide information on the open redirect vulnerability in UrlHandlerFilter, affecting Spring Framework versions 6.2.0-6.2.19 and 7.0.0-7.0.8. The issue applies to both Spring MVC and Spring WebFlux filter variants. Defenders should verify vendor-provided patches or updates to prevent potential open redirect attacks. The vulnerability has a medium severity with a CVSS score of 6.1.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47883 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47883
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47883 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47883
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://spring.io/security/cve-2026-47883
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.