PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-47887 Spring CVE debrief

CVE-2026-47887 is a medium-severity open redirect vulnerability in Spring Framework. The vulnerability occurs when using UrlFileNameViewController with an end-of-path mapping and no configured prefix. Affected versions include 5.2.25.RELEASE to 7.0.8. Defenders and developers should assess exposure and prioritize remediation to prevent potential phishing and data exposure attacks. The CVE record and NVD detail page provide information on the vulnerability. The open redirect vulnerability could lead to potential phishing attacks, exposure of sensitive data, and reputation damage.

Vendor
Spring
Product
Spring Framework
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-27
Original CVE updated
2026-09-10
Advisory published
2026-08-27
Advisory updated
2026-09-10

Who should care

Defenders and developers using Spring Framework applications should assess exposure and prioritize remediation to prevent potential phishing and data exposure attacks. Security teams should review and update Spring Framework versions to the latest patched versions and implement compensating controls to mitigate open redirect attacks. Operators and platform administrators should verify affected versions and assess exposure. Vulnerability management teams, ,

Why it matters

CVE-2026-47887 is a medium-severity open redirect vulnerability in Spring Framework that requires assessment and remediation to prevent potential phishing and data exposure attacks.

  • Potential phishing attacks through open redirect
  • Exposure of sensitive data through redirect
  • Reputation damage due to successful attacks
  • Need for verification of affected versions and remediation

Technical summary

The Spring Framework is vulnerable to an open redirect attack when using UrlFileNameViewController with an end-of-path mapping and no configured prefix. This affects versions 5.2.25.RELEASE to 7.0.8. The vulnerability could lead to potential phishing attacks, exposure of sensitive data, and reputation damage. Defenders and developers should assess exposure and prioritize remediation to prevent potential attacks. The CVE record and NVD detail page provide information on the vulnerability and affected versions. The open redirect vulnerability could be exploited to redirect users to malicious websites, potentially leading to phishing attacks and data exposure.

Defensive priority

Assess exposure and prioritize remediation for Spring Framework applications using UrlFileNameViewController with an end-of-path mapping and no configured prefix.

Recommended defensive actions

  • Review and update Spring Framework versions to the latest patched versions
  • Assess exposure of Spring Framework applications using UrlFileNameViewController
  • Implement compensating controls to mitigate open redirect attacks
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The CVE record and NVD detail page provide information on the open redirect vulnerability in Spring Framework versions 5.2.25.RELEASE to 7.0.8. The vulnerability occurs when using UrlFileNameViewController with an end-of-path mapping and no configured prefix. Defenders should verify affected versions and assess exposure. The CVE Program and NVD records provide source-provided CVE metadata and official vulnerability assessment.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-47887 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-47887

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-47887 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47887

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.