SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47893

HIGH · CVSS 7.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Spring WebFlux applications that support WebSocket connections may inadvertently expose sensitive user information through exception messages that include request headers. This vulnerability affects multiple versions of the Spring Framework, from 5.2.25.RELEASE up to 7.0.8. Organizations utilizing these affected versions should prioritize remediation to protect user data from potential leakage.

CVE
CVE-2026-47893
Severity
HIGH
CVSS
7.5
EPSS
0.24%

Original NVD Description

A Spring WebFlux application that supports WebSocket connections may expose indirectly sensitive user information by including request headers in an exception reason. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.25.RELEASE and earlier

Related CVEs

Other vulnerabilities affecting the same vendor(s)