CVE-2026-47883: VMware Spring Framework

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

Affected products

  • VMware Spring Framework: from 6.2.0, before 6.2.20 (fixed in 6.2.20); from 7.0.0, before 7.0.8.1 (fixed in 7.0.8.1)

Published 2026-08-27. Last modified 2026-09-10.