Intel

AIKIDO-2026-22960

spring-security-core is vulnerable to Open Redirect

Open RedirectCVE-2026-41008 Published Jun 15, 2026

61

Medium Risk

This Affects:

JAVAspring-security-core
7.0.0 - 7.0.5
Fixed in 7.0.6
Are you affected? Scan for Free

TL;DR

Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-security-core is vulnerable to Open Redirect in versions 7.0.0 - 7.0.5.

How to fix this

Upgrade the org.springframework.security:spring-security-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform