Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41847

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 4.8

Описание

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

A flaw was found in Spring WebFlux applications. This vulnerability allows for a security bypass when using the Kotlin Router DSL. An attacker could exploit this to bypass security restrictions, potentially leading to unauthorized access.

Отчет

Red Hat ships Spring WebFlux in Fuse 7. The affected version is set to AFFECTED/DEFER as the CVSS score (4.8) is below the 7.0 threshold. This flaw only affects applications using the Kotlin Router DSL.

Меры по смягчению последствий

This vulnerability only applies when using Kotlin Router DSL. Applications using Java-based routing are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7spring-webfluxFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-551
https://bugzilla.redhat.com/show_bug.cgi?id=2486698Spring Framework: Spring WebFlux applications: Security bypass when using Kotlin Router DSL

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
3 месяца назад

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 4.8
nvd
3 месяца назад

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL. Affected versions: Spring Framework 5.3.0 through 5.3.48.

CVSS3: 4.8
debian
3 месяца назад

Spring WebFlux applications may be vulnerable to a security bypass whe ...

CVSS3: 4.8
github
3 месяца назад

Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL

4.8 Medium

CVSS3