SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47889

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

WebFlux applications utilizing the Jetty 12 Core reactive adapter are vulnerable due to the serialization of response cookies lacking the sameSite attribute, which can lead to potential cross-site request forgery (CSRF) attacks. Organizations using Spring Framework versions 6.2.0 to 6.2.19 and 7.0.0 to 7.0.8 should prioritize addressing this vulnerability to enhance their application's security posture against cookie-related exploits.

CVE
CVE-2026-47889
Severity
HIGH
CVSS
7.5
EPSS
0.25%

Original NVD Description

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

Related CVEs

Other vulnerabilities affecting the same vendor(s)