CVE-2026-47893
published 2026-08-27CVE-2026-47893: A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception…
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.24%
15.7th percentile
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_framework | <= 5.2.25.RELEASE | — |
| spring | spring_framework | 5.3.0 – 5.3.49 | — |
| spring | spring_framework | 6.0.0 – 6.0.30 | — |
| spring | spring_framework | 6.1.0 – 6.1.28 | — |
| spring | spring_framework | 6.2.0 – 6.2.19 | — |
| spring | spring_framework | 7.0.0 – 7.0.8 | — |
| vmware | spring_framework | < 5.2.26 | 5.2.26 |
| vmware | spring_framework | >= 5.3.0 < 5.3.50 | 5.3.50 |
| vmware | spring_framework | >= 6.0.0 < 6.0.31 | 6.0.31 |
| vmware | spring_framework | >= 6.1.0 < 6.1.29 | 6.1.29 |
| vmware | spring_framework | >= 6.2.0 < 6.2.20 | 6.2.20 |
| vmware | spring_framework | >= 7.0.0 < 7.0.8.1 | 7.0.8.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason.
ghsa_unreviewed·2026-08-27
CVE-2026-47893 [HIGH] CWE-209 A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason.
A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
Spring Framework 6.1.0 - 6.1.28
Spring Framework 6.0.0 - 6.0.30
Spring Framework 5.3.0 - 5.3.49
Spring Framework 5.2.25.RELEASE and earlier
VulDB
Spring Framework up to 7.0.8 WebFlux information exposure (WID-SEC-2026-2955)
vuldb·2026-08-27·CVSS 7.5
CVE-2026-47893 [HIGH] Spring Framework up to 7.0.8 WebFlux information exposure (WID-SEC-2026-2955)
A vulnerability labeled as problematic has been found in Spring Framework up to 7.0.8. Affected is an unknown function of the component WebFlux. Such manipulation leads to information exposure through error message.
This vulnerability is listed as CVE-2026-47893. The attack may be performed from remote. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-27
Published