Intel

AIKIDO-2026-791233

spring-security-oauth2-authorization-server is vulnerable to Open Redirect

Open RedirectCVE-2026-41008 Published Today

61

Medium Risk

This Affects:

Are you affected? Scan for Free

TL;DR

Spring Security Authorization Server's authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a malicious authorization request containing an invalid request_uri and an arbitrary, unvalidated redirect_uri, which can lead to an Open Redirect vulnerability.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-security-oauth2-authorization-server is vulnerable to Open Redirect in versions 1.5.0 - 1.5.7.

How to fix this

Upgrade the org.springframework.security:spring-security-oauth2-authorization-server library to the patch version.