PatchSiren cyber security CVE debrief
CVE-2026-47887 Spring CVE debrief
CVE-2026-47887 is a medium-severity open redirect vulnerability in Spring Framework. The vulnerability occurs when using UrlFileNameViewController with an end-of-path mapping and no configured prefix. Affected versions include 5.2.25.RELEASE to 7.0.8. Defenders and developers should assess exposure and prioritize remediation to prevent potential phishing and data exposure attacks. The CVE record and NVD detail page provide information on the vulnerability. The open redirect vulnerability could lead to potential phishing attacks, exposure of sensitive data, and reputation damage.
- Vendor
- Spring
- Product
- Spring Framework
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-27
- Original CVE updated
- 2026-09-10
- Advisory published
- 2026-08-27
- Advisory updated
- 2026-09-10
Who should care
Defenders and developers using Spring Framework applications should assess exposure and prioritize remediation to prevent potential phishing and data exposure attacks. Security teams should review and update Spring Framework versions to the latest patched versions and implement compensating controls to mitigate open redirect attacks. Operators and platform administrators should verify affected versions and assess exposure. Vulnerability management teams, ,
Why it matters
CVE-2026-47887 is a medium-severity open redirect vulnerability in Spring Framework that requires assessment and remediation to prevent potential phishing and data exposure attacks.
- Potential phishing attacks through open redirect
- Exposure of sensitive data through redirect
- Reputation damage due to successful attacks
- Need for verification of affected versions and remediation
Technical summary
The Spring Framework is vulnerable to an open redirect attack when using UrlFileNameViewController with an end-of-path mapping and no configured prefix. This affects versions 5.2.25.RELEASE to 7.0.8. The vulnerability could lead to potential phishing attacks, exposure of sensitive data, and reputation damage. Defenders and developers should assess exposure and prioritize remediation to prevent potential attacks. The CVE record and NVD detail page provide information on the vulnerability and affected versions. The open redirect vulnerability could be exploited to redirect users to malicious websites, potentially leading to phishing attacks and data exposure.
Defensive priority
Assess exposure and prioritize remediation for Spring Framework applications using UrlFileNameViewController with an end-of-path mapping and no configured prefix.
Recommended defensive actions
- Review and update Spring Framework versions to the latest patched versions
- Assess exposure of Spring Framework applications using UrlFileNameViewController
- Implement compensating controls to mitigate open redirect attacks
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The CVE record and NVD detail page provide information on the open redirect vulnerability in Spring Framework versions 5.2.25.RELEASE to 7.0.8. The vulnerability occurs when using UrlFileNameViewController with an end-of-path mapping and no configured prefix. Defenders should verify affected versions and assess exposure. The CVE Program and NVD records provide source-provided CVE metadata and official vulnerability assessment.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-47887 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-47887
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-47887 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-47887
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://spring.io/security/cve-2026-47887
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.