Maven: org.springframework:spring-webflux

CVE-2026-47892

Safety vulnerability ID: SFTY-20260827-26369

Affected versions of the `org.springframework:spring-webflux` package are vulnerable to Improper Authorization because a header predicate on a functional endpoint is not applied to a pre-flight request. A WebFlux application that uses functional endpoints and is deployed with `DispatcherServlet` evaluates route predicates for the pre-flight differently from the request that follows it, so a predicate written to require a header does not hold there. An attacker can use a crafted pre-flight request to reach a route the predicate exists to keep them out of.

Created at: Sep 10, 2026Updated at: Sep 10, 2026

Overview

org.springframework:spring-webflux – Incorrect Authorization

Advisory

org.springframework:spring-webflux – Incorrect Authorization

Affected Package

Affecting org.springframework:spring-webflux package, versions>= 5.2.5, < 5.2.26>= 5.3.0, < 5.3.50>= 6.0.0, < 6.0.31>= 6.1.0, < 6.1.29>= 6.2.0, < 6.2.20>= 7.0.0, < 7.0.8.1

Also affects

---

How to Fix

Upgradeorg.springframework:spring-webfluxto7.0.9or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more