CVE-2026-59355: Broadcom Spring Authorization Server

Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.

In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an attacker-controlled site.

Affected products

  • Broadcom Spring Authorization Server: from 1.5.0, before 1.5.7.1 (fixed in 1.5.7.1)

Published 2026-08-27. Last modified 2026-09-01.