Medium severity6.1NVD Advisory· Published Jun 10, 2026· Updated Jun 10, 2026
CVE-2026-41706
CVE-2026-41706
Description
Spring Security's CookieRequestCache and CookieServerRequestCache store the pre-authentication request URL in a browser cookie so that users can be redirected back to their intended destination after a successful login. In affected versions, the full absolute URL is stored in the cookie and is used without validation as the post-login redirect target.
Affected versions: Spring Security 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework.security:spring-security-webMaven | >= 7.0.0, < 7.0.6 | 7.0.6 |
org.springframework.security:spring-security-webMaven | >= 6.5.0, < 6.5.11 | 6.5.11 |
org.springframework.security:spring-security-webMaven | >= 6.3.0, <= 6.3.16 | — |
org.springframework.security:spring-security-webMaven | >= 5.8.0, <= 5.8.25 | — |
org.springframework.security:spring-security-webMaven | <= 5.7.23 | — |
Affected products
4- osv-coords3 versionspkg:apk/chainguard/apache-nifi-registry-2.11pkg:maven/org.springframework.security/spring-security-webpkg:apk/chainguard/geoserver-3.0
< 2.11.0-r1+ 2 more
- (no CPE)range: < 2.11.0-r1
- (no CPE)range: >= 7.0.0, < 7.0.6
- (no CPE)range: < 3.0.1-r0
- Range: 5.7.0 through 5.7.23; 5.8.0 through 5.8.25; 6.3.0 through 6.3.16; 6.4.0 through 6.4.16; 6.5.0 through 6.5.10; 7.0.0 through 7.0.5
Patches
Vulnerability mechanics
References
5News mentions
0No linked articles in our index yet.