CVE-2026-41847

Updated on 09 Jun 2026

Severity

4.8 Medium severity

Details

CVSS score
4.8
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Overview

About vulnerability

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.

Affected versions: Spring Framework 5.3.0 through 5.3.48.

Details

Affected packages:
Spring Data @ 3.7.18 (+3050 more)

Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.

Affected versions: Spring Framework 5.3.0 through 5.3.48.

Fixes