CVE-2026-47884
published 2026-08-27CVE-2026-47884: Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where…
PriorityP350critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.42%
35.6th percentile
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_framework | <= 5.2.25.RELEASE | — |
| spring | spring_framework | 5.3.0 – 5.3.49 | — |
| spring | spring_framework | 6.0.0 – 6.0.30 | — |
| spring | spring_framework | 6.1.0 – 6.1.28 | — |
| spring | spring_framework | 6.2.0 – 6.2.19 | — |
| spring | spring_framework | 7.0.0 – 7.0.8 | — |
| vmware | spring_framework | < 5.2.26 | 5.2.26 |
| vmware | spring_framework | >= 5.3.0 < 5.3.50 | 5.3.50 |
| vmware | spring_framework | >= 6.0.0 < 6.0.31 | 6.0.31 |
| vmware | spring_framework | >= 6.1.0 < 6.1.29 | 6.1.29 |
| vmware | spring_framework | >= 6.2.0 < 6.2.20 | 6.2.20 |
| vmware | spring_framework | >= 7.0.0 < 7.0.8.1 | 7.0.8.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specifie
ghsa_unreviewed·2026-08-27
CVE-2026-47884 [CRITICAL] CWE-22 Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specifie
Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping that results in view rendering, and where the view name is not explicitly specified.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
Red Hat
org.springframework/spring-webmvc: Spring Framework: Remote Code Execution via improper path limitation in XsltView
vendor_redhat·2026-08-27·CVSS 9.8
CVE-2026-47884 [CRITICAL] CWE-22 org.springframework/spring-webmvc: Spring Framework: Remote Code Execution via improper path limitation in XsltView
org.springframework/spring-webmvc: Spring Framework: Remote Code Execution via improper path limitation in XsltView
A flaw was found in the XsltView component of Spring MVC applications. This
vulnerability could allow a remote, unauthenticated attacker to perform
Server-Side Request Forgery (SSRF), enabling them to make unauthorized
requests from the server, and potentially achieve Remote Code Execution
(RCE), allowing them to execute arbitrary code on the affected system. This
occurs when an application uses a broad URL mapping that results in view
rendering without explicitly specifying the view name, allowing an attacker
to control which stylesheet is loaded.
Statement: Red Hat rates this vulnerability as Critical, a higher severity than the
Medium rating assigned by the Spring projec
No detection rules found.
No public exploits indexed.
2026-08-27
Published