GHSA-j94g-vwjh-xffqMediumCVSS 6.1

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching...

Published
August 27, 2026
Last Modified
August 27, 2026

🔗 CVE IDs covered (1)

📋 Description

UrlHandlerFilter can be vulnerable to an open redirect when configured with very broadly matching patterns. The issue applies to the filter variants in both Spring MVC and Spring WebFlux. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

🔗 References (3)