Spring Framework Open Redirect in UrlHandlerFilter
33Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendcvss 6.1epss 0.2%
from disclosure to weapon0 days
Published on NVDAug 27
1st PoCMay 20
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Affected products
Spring · Spring Frameworkpublic PoCs found — 1
githubgithub.com/daehyuh/CVE-2026-47883★ 0⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.