Home

Description

Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute URL is stored in the cookie and is used without validation as the post-login redirect target. Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.

PUBLISHED Reserved 2026-04-22 | Published 2026-06-09 | Updated 2026-06-10 | Assigner vmware




MEDIUM: 6.1CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Problem types

CWE-601: URL Redirection to Untrusted Site (Open Redirect)

Product status

Default status
unaffected

5.7.0 (custom) before 5.7.24
affected

5.8.0 (custom) before 5.8.26
affected

6.3.0 (custom) before 6.3.17
affected

6.4.0 (custom) before 6.4.17
affected

6.5.0 (custom) before 6.5.11
affected

7.0.0 (custom) before 7.0.6
affected

References

spring.io/security/cve-2026-41706

cve.org (CVE-2026-41706)

nvd.nist.gov (CVE-2026-41706)

Download JSON