Medium severity6.1NVD Advisory· Published Aug 27, 2026
CVE-2026-59355
CVE-2026-59355
Description
In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an attacker-controlled site.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: 1.5.0 - 1.5.7
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.