{"id":"CVE-2026-47887","title":"A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpri…","summary":"A Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpri…","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","cwe":["CWE-601"],"vendor":"vmware","product":"spring_framework","affected":["spring_framework < 5.2.26","spring_framework >= 5.3.0, < 5.3.50","spring_framework >= 6.0.0, < 6.0.31","spring_framework >= 6.1.0, < 6.1.29","spring_framework >= 6.2.0, < 6.2.20","spring_framework >= 7.0.0, < 7.0.8.1"],"patched":["spring_framework 7.0.8.1"],"published":"2026-08-27","updated":"2026-09-10","sourceUpdated":"2026-09-10T14:19:58.513","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-47887","references":[{"url":"https://spring.io/security/cve-2026-47887","label":"security@vmware.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47887.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-47887"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2524838"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47887"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47887"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00172,"epssPercentile":0.06882,"ingestedAt":"2026-09-10T14:51:56.240Z","scores":{"nvd":6.1,"vendor":5.4},"slug":"CVE-2026-47887","body":"## Overview\n\nA Spring MVC application that uses UrlFileNameViewController that is mapped with an end-of-path, and does not have a configured prefix is vulnerable to an open redirect.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.25.RELEASE and earlier\n\n## Affected\n\n- `spring_framework < 5.2.26`\n- `spring_framework >= 5.3.0, < 5.3.50`\n- `spring_framework >= 6.0.0, < 6.0.31`\n- `spring_framework >= 6.1.0, < 6.1.29`\n- `spring_framework >= 6.2.0, < 6.2.20`\n- `spring_framework >= 7.0.0, < 7.0.8.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `spring_framework 7.0.8.1`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · affected: Red Hat build of Apache Camel - HawtIO 4, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Fuse 7, Red Hat OpenShift Dev Spaces · no fix planned: Red Hat build of Apache Camel - HawtIO 4, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Fuse 7, … · updated 2026-09-16 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47887.json)","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}