---
id: CVE-2026-47892
aliases:
  - GHSA-9qf2-26p9-2q2q
title: Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints
summary: Spring Framework Header Predicate Bypass in WebFlux Functional Endpoints
severity: critical
cvss: 9.8
cwe:
  - CWE-863
vendor: springframework
product: 'org.springframework:spring-webflux'
ecosystem: maven
affected:
  - 'org.springframework:spring-webflux >= 5.2.5.RELEASE, <= 5.2.25.RELEASE'
  - 'org.springframework:spring-webflux >= 5.3.0, <= 5.3.49'
  - 'org.springframework:spring-webflux >= 6.0.0, <= 6.0.30'
  - 'org.springframework:spring-webflux >= 6.1.0, <= 6.1.28'
  - 'org.springframework:spring-webflux >= 6.2.0, <= 6.2.19'
  - 'org.springframework:spring-webflux >= 7.0.0, <= 7.0.8'
patched:
  - 'org.springframework:spring-webflux 7.0.9'
published: '2026-08-27'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T13:20:48Z'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-9qf2-26p9-2q2q'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-47892'
  - url: 'https://spring.io/security/cve-2026-47892'
  - url: 'https://github.com/advisories/GHSA-9qf2-26p9-2q2q'
tags:
  - ghsa
  - maven
epss: 0.00529
epssPercentile: 0.4287
ingestedAt: '2026-10-07T13:31:04.600Z'
---

## Overview

A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE

## Affected packages

- `org.springframework:spring-webflux >= 5.2.5.RELEASE, <= 5.2.25.RELEASE`
- `org.springframework:spring-webflux >= 5.3.0, <= 5.3.49`
- `org.springframework:spring-webflux >= 6.0.0, <= 6.0.30`
- `org.springframework:spring-webflux >= 6.1.0, <= 6.1.28`
- `org.springframework:spring-webflux >= 6.2.0, <= 6.2.19`
- `org.springframework:spring-webflux >= 7.0.0, <= 7.0.8`

## Remediation

Upgrade to a patched release:

- `org.springframework:spring-webflux 7.0.9`
