Intel

AIKIDO-2026-22960

spring-security-core is vulnerable to Open Redirect

Open RedirectCVE-2026-41008 Published Today

61

Medium Risk

This Affects:

JAVAspring-security-core
7.0.0 - 7.0.5
Fixed in 7.0.6
Are you affected? Scan for Free

TL;DR

Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-security-core is vulnerable to Open Redirect in versions 7.0.0 - 7.0.5.

How to fix this

Upgrade the org.springframework.security:spring-security-core library to the patch version.