Project Subscriptions
No data.
No advisories yet.
Solution
Upgrade to Spring Authorization Server 1.5.8 (OSS) or 1.5.7.1 (Enterprise Support customers). No additional mitigation is required after upgrading.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-59355 |
|
Thu, 27 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an attacker-controlled site. | |
| Title | Spring Authorization Server: Open Redirect via request_uri parameter | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-08-27T13:37:30.618Z
Reserved: 2026-07-04T18:14:46.172Z
Link: CVE-2026-59355
Updated: 2026-08-27T13:37:25.394Z
Status : Received
Published: 2026-08-27T10:16:36.197
Modified: 2026-08-27T17:18:58.010
Link: CVE-2026-59355
No data.
OpenCVE Enrichment
Updated: 2026-08-27T10:30:06Z