CVE-2026-47892Critical· 9.8▾ MidnightSpring Framework Header Predicate Bypass in WebFlux Functional Endpoints
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.5%
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE
org.springframework:spring-webflux >= 5.2.5.RELEASE, <= 5.2.25.RELEASEorg.springframework:spring-webflux >= 5.3.0, <= 5.3.49org.springframework:spring-webflux >= 6.0.0, <= 6.0.30org.springframework:spring-webflux >= 6.1.0, <= 6.1.28org.springframework:spring-webflux >= 6.2.0, <= 6.2.19org.springframework:spring-webflux >= 7.0.0, <= 7.0.8Upgrade to a patched release:
org.springframework:spring-webflux 7.0.9Connected by shared product, vendor, weakness, or advisory.
CVE-2026-47890Critical· 9.8Spring Framework Server Sent Event stream corruption while rendering fragments
CVE-2024-38819High· 7.5Spring Framework Path Traversal vulnerability
CVE-2020-3578Medium· 5.3A vulnerability in the web services interface of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass a configured access rule and ac…
CVE-2024-6593Critical· 9.1Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained netwo…
CVE-2026-41731High· 8.1In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
CVE-2026-41726Medium· 6.5In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header