VMwareCVE-2026-47883
VMware Spring Framework: open redirect
Medium6.1CVE-2026-47883 · Published Aug 27, 2026 · updated Sep 10, 2026
UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Spring Framework Product | >= 7.0.0, <= 7.0.8 | No fix yet |
| >= 6.2.0, <= 6.2.19 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-601
More VMware advisories
All VMware| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 27 | VMware Spring AMQP: resource leak | Medium6.5 | No fix yet |
| Aug 27 | VMware Spring Integration: race condition | Medium4.2 | No fix yet |
| Aug 27 | VMware Spring Integration: improper input validation | Medium6.3 | No fix yet |
| Aug 27 | VMware Spring Integration: race condition | High8.2 | No fix yet |
| Aug 27 | VMware Spring Integration: unsafe deserialization | High8.0 | No fix yet |
| Aug 27 | VMware Spring Integration: link following | Medium6.8 | No fix yet |