PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47883 Spring CVE debrief

CVE-2026-47883 debrief based on CVE Program and NVD records. The vulnerability affects Spring Framework's UrlHandlerFilter, allowing open redirects when configured with broadly matching patterns. This issue impacts both Spring MVC and Spring WebFlux filter variants in versions 6.2.0-6.2.19 and 7.0.0-7.0.8. Defenders and security teams should assess exposure and prioritize remediation or compensating controls for affected versions. The CVE record and NVD vulnerability detail page provide information on the open redirect vulnerability.

Vendor
Spring
Product
Spring Framework
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-27
Original CVE updated
2026-09-10
Advisory published
2026-08-27
Advisory updated
2026-09-10

Who should care

Defenders and security teams responsible for Spring Framework deployments should assess exposure and prioritize remediation or compensating controls for affected versions. This includes reviewing compensating controls for exposed systems while remediation is scheduled and verified, and checking relevant monitoring, detection, and logs for exposed assets that need extra review.

Why it matters

CVE-2026-47883 is a medium-severity vulnerability in Spring Framework's UrlHandlerFilter, allowing open redirects when configured with broadly matching patterns. Defenders and security teams should assess exposure, prioritize remediation or compensating controls for affected versions 6.2.0-6.2.19 and 7.0.0-7.0.8, and verify vendor-provided patches or updates to prevent potential open redirect attacks.

  • Potential open redirect attacks may lead to phishing or other malicious activities
  • Exposure of sensitive data or systems may occur if not properly mitigated
  • Verification of vendor-provided patches or updates is necessary to prevent exploitation
  • Remediation priority is medium due to the CVSS score of 6.1

Technical summary

The UrlHandlerFilter in Spring Framework is vulnerable to an open redirect when configured with very broadly matching patterns. This issue affects both Spring MVC and Spring WebFlux filter variants in versions 6.2.0-6.2.19 and 7.0.0-7.0.8. The vulnerability has a medium severity with a CVSS score of 6.1. Defenders and security teams should assess exposure and prioritize remediation or compensating controls for affected versions. The CVE record and NVD vulnerability detail page provide information on the open redirect vulnerability.

Defensive priority

Assess exposure and prioritize remediation for Spring Framework versions 6.2.0-6.2.19 and 7.0.0-7.0.8

Recommended defensive actions

  • Assess exposure of Spring Framework versions 6.2.0-6.2.19 and 7.0.0-7.0.8 in your environment
  • Prioritize remediation or apply compensating controls for affected versions
  • Verify vendor-provided patches or updates for Spring Framework
  • Monitor for potential open redirect attacks
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and NVD vulnerability detail page provide information on the open redirect vulnerability in UrlHandlerFilter, affecting Spring Framework versions 6.2.0-6.2.19 and 7.0.0-7.0.8. The issue applies to both Spring MVC and Spring WebFlux filter variants. Defenders should verify vendor-provided patches or updates to prevent potential open redirect attacks. The vulnerability has a medium severity with a CVSS score of 6.1.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47883 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47883

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47883 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47883

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.