Junglewise Threat Intelligence

CVE-2026-41847: VMware Spring Framework security bypass in WebFlux Kotlin Router DSL

CVE-2026-41847 · Severity: medium · CVSS 4.8 · Published 2026-06-09

Technologies: VMware Spring Framework. Vendors: VMware, Maven.

Executive brief

Spring Framework is a popular tool used by developers to build Java-based web applications. A security flaw has been identified in its WebFlux component when using the Kotlin programming language to define web routes. This vulnerability could allow an attacker to bypass security filters, potentially gaining unauthorized access to restricted parts of the application or its data.

Technical details

A security filter bypass vulnerability exists in Spring Framework's WebFlux component, specifically affecting applications utilizing the Kotlin Router DSL. The flaw is classified as Improper Access Control (CWE-284) and occurs when security constraints are incorrectly applied or bypassed due to the way routes are handled in the Kotlin DSL. An unauthenticated attacker can exploit this over the network, though the attack complexity is rated as high. Successful exploitation could lead to a partial loss of confidentiality and integrity. The vulnerability affects Spring Framework versions 5.3.0 through 5.3.48; users are advised to monitor for patches (e.g., version 5.3.49).

Affected products

  • VMware Spring Framework 5.3.0 through 5.3.48

Timeline

  • 2026-06-09: disclosed: NVD and GitHub Advisory published
  • 2026-07-30: advisory: GitHub Advisory updated and reviewed

References

Related threats