Intel

AIKIDO-2026-11160

spring-webflux is vulnerable to Open Redirect

Open RedirectCVE-2026-41844 Published Jun 11, 2026

42

Medium Risk

This Affects:

JAVAspring-webflux
5.3.0 - 6.2.18
Fixed in 6.2.19
7.0.0 - 7.0.7
Fixed in 7.0.8
Are you affected? Scan for Free

TL;DR

A Spring MVC or Spring WebFlux application which configures a mapping for"/**" where the view name is not explicitly specified allows an attacker to craft a link resulting in a 302 redirect to an arbitrary external host via the redirect: prefix.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-webflux is vulnerable to Open Redirect in versions 5.3.0 - 6.2.18 and 7.0.0 - 7.0.7.

How to fix this

Upgrade the org.springframework:spring-webflux library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform