Maven: org.springframework:spring-webflux
CVE-2026-47892
Safety vulnerability ID: SFTY-20260827-26369
Affected versions of the `org.springframework:spring-webflux` package are vulnerable to Improper Authorization because a header predicate on a functional endpoint is not applied to a pre-flight request. A WebFlux application that uses functional endpoints and is deployed with `DispatcherServlet` evaluates route predicates for the pre-flight differently from the request that follows it, so a predicate written to require a header does not hold there. An attacker can use a crafted pre-flight request to reach a route the predicate exists to keep them out of.
Overview
org.springframework:spring-webflux – Incorrect Authorization
Advisory
org.springframework:spring-webflux – Incorrect Authorization
Affected Package
Also affects
---
How to Fix
Mitigation and Workarounds
---
Vulnerable Functions
Functions linked to known vulnerabilities.
Verified by Safety
Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.
Learn more