Home

Description

A Spring MVC or Spring WebFlux application which configures a mapping for "/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48.

PUBLISHED Reserved 2026-04-22 | Published 2026-06-09 | Updated 2026-06-09 | Assigner vmware




MEDIUM: 4.2CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

Problem types

CWE-601: URL Redirection to Untrusted Site (Open Redirect)

Product status

Default status
unaffected

7.0.0 (custom) before 7.0.8
affected

6.2.0 (custom) before 6.2.19
affected

6.1.0 (custom) before 6.1.28
affected

5.3.0 (custom) before 5.3.49
affected

References

spring.io/security/cve-2026-41844

cve.org (CVE-2026-41844)

nvd.nist.gov (CVE-2026-41844)

Download JSON