CVE-2026-47892
published 2026-08-27CVE-2026-47892: A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request…
PriorityP353critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.36%
29.8th percentile
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| devspaces | openvsx-rhel9 | — | — |
| devspaces | pluginregistry-rhel9 | — | — |
| pki-core_10.6 | resteasy | — | — |
| pki-deps_10.6 | resteasy | — | — |
| redhat | resteasy | — | — |
| spring | spring_framework | 5.2.5.RELEASE – 5.2.25.RELEASE | — |
| spring | spring_framework | 5.3.0 – 5.3.49 | — |
| spring | spring_framework | 6.0.0 – 6.0.30 | — |
| spring | spring_framework | 6.1.0 – 6.1.28 | — |
| spring | spring_framework | 6.2.0 – 6.2.19 | — |
| spring | spring_framework | 7.0.0 – 7.0.8 | — |
| vmware | spring_framework | >= 5.2.5 < 5.2.26 | 5.2.26 |
| vmware | spring_framework | >= 5.3.0 < 5.3.50 | 5.3.50 |
| vmware | spring_framework | >= 6.0.0 < 6.0.31 | 6.0.31 |
| vmware | spring_framework | >= 6.1.0 < 6.1.29 | 6.1.29 |
| vmware | spring_framework | >= 6.2.0 < 6.2.20 | 6.2.20 |
| vmware | spring_framework | >= 7.0.0 < 7.0.8.1 | 7.0.8.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.springframework/spring-webflux: Spring Framework: Header Predicate Bypass in WebFlux Functional Endpoints
vendor_redhat·2026-08-27·CVSS 9.8
CVE-2026-47892 [CRITICAL] CWE-807 org.springframework/spring-webflux: Spring Framework: Header Predicate Bypass in WebFlux Functional Endpoints
org.springframework/spring-webflux: Spring Framework: Header Predicate Bypass in WebFlux Functional Endpoints
A flaw was found in Spring Framework. This vulnerability allows a header predicate bypass to occur in a pre-flight request within a WebFlux application that uses functional endpoints and is deployed with DispatcherServlet. This bypass could potentially lead to unexpected behavior or security policy circumvention.
Package: pki-core:10.6/resteasy (Red Hat Enterprise Linux 8) - Affected
Package: pki-deps:10.6/resteasy (Red Hat Enterprise Linux 8) - Affected
Package: resteasy (Red Hat Enterprise Linux 9) - Affected
Package: spring-webmvc (Red Hat Fuse 7) - Out of support scope
Package: devspaces/openvsx-rhel9 (Red Hat OpenShift Dev Spaces) - Affected
Package: devspaces/pluginreg
VulDB
VMware Spring Framework up to 7.0.8 WebFlux authorization (WID-SEC-2026-2955)
vuldb·2026-08-27·CVSS 9.8
CVE-2026-47892 [CRITICAL] VMware Spring Framework up to 7.0.8 WebFlux authorization (WID-SEC-2026-2955)
A vulnerability identified as critical has been detected in VMware Spring Framework up to 7.0.8. This impacts an unknown function of the component WebFlux. This manipulation causes incorrect authorization.
This vulnerability is tracked as CVE-2026-47892. The attack is possible to be carried out remotely. No exploit exists.
GHSA
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request.
ghsa_unreviewed·2026-08-27
CVE-2026-47892 [CRITICAL] CWE-863 A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request.
A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a pre-flight request.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.5.RELEASE - 5.2.25.RELEASE
No detection rules found.
No public exploits indexed.
2026-08-27
Published