Executive brief
Spring Framework, a widely used tool for building Java-based web applications, contains a vulnerability that could allow attackers to redirect users to malicious websites. By tricking a user into clicking a specially crafted link, an attacker can bypass security checks and send the user to an external site that might host phishing content or malware. This issue primarily affects applications with specific broad URL configurations and can damage a company's reputation or lead to credential theft.
Technical details
An open redirect vulnerability (CWE-601) exists in Spring MVC and Spring WebFlux when a handler mapping is configured for the root pattern '/**' without an explicitly defined view name. In this configuration, the framework may process user-supplied input as a view name, allowing the use of the 'redirect:' prefix to trigger a 302 Found response to an arbitrary external URL. Exploitation requires a remote attacker to entice a user to click a malicious link (User Interaction required). The vulnerability is mitigated by high attack complexity as it depends on specific application routing configurations. Patches are available in versions 7.0.8 and 6.2.19.
Affected products
- VMware Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 through 5.3.48
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory
- 2026-07-30: patched
References
- https://spring.io/security/cve-2026-41844
- https://github.com/spring-projects/spring-framework/commit/3aaec987651cf82fd4ed7e0ed9b3deddcdf58853
- https://github.com/spring-projects/spring-framework/commit/7add5243b9db13a9f8e765c8ab8545c8e8fe606b
- https://github.com/spring-projects/spring-framework/releases/tag/v6.2.19
- https://github.com/spring-projects/spring-framework/releases/tag/v7.0.8