Feed/CVE-2026-41008
CVE-2026-41008MEDIUMCVSS 6.1

CVE-2026-41008

Published Jun 10, 2026·Updated Aug 12, 2026

NVD Description

Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability. Affected versions: Spring Security 7.0.0 through 7.0.5. Spring Authorization Server 1.5.0 through 1.5.7.

Affected Packages (1)

org.springframework.security:spring-security-oauth2-authorization-serverMAVEN
From 7.0.0
Fixed in = 7.0.5

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free