CVE-2026-47889
published 2026-08-27CVE-2026-47889: A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8…
PriorityP341high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.25%
16.7th percentile
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_framework | 6.2.0 – 6.2.19 | — |
| spring | spring_framework | 7.0.0 – 7.0.8 | — |
| vmware | spring_framework | >= 6.2.0 < 6.2.20 | 6.2.20 |
| vmware | spring_framework | >= 7.0.0 < 7.0.8.1 | 7.0.8.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute.
ghsa_unreviewed·2026-08-27
CVE-2026-47889 [HIGH] CWE-1275 A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute.
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
VulDB
VMware Spring Framework up to 6.2.19/7.0.8 Cookies sameSite sensitive cookie with improper samesite attribute (WID-SEC-2026-2955)
vuldb·2026-08-27·CVSS 7.5
CVE-2026-47889 [HIGH] VMware Spring Framework up to 6.2.19/7.0.8 Cookies sameSite sensitive cookie with improper samesite attribute (WID-SEC-2026-2955)
A vulnerability was found in VMware Spring Framework up to 6.2.19/7.0.8. It has been rated as critical. The impacted element is an unknown function of the component Cookies. The manipulation of the argument sameSite leads to sensitive cookie with improper samesite attribute.
This vulnerability is referenced as CVE-2026-47889. Remote exploitation of the attack is possible. No exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-27
Published