Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to Spring Authorization Server 1.5.8 (OSS) or 1.5.7.1 (Enterprise Support customers). No additional mitigation is required after upgrading.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-59355 |
|
Thu, 27 Aug 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 27 Aug 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In versions of Spring Authorization Server 1.5.0 through 1.5.7, the authorization endpoint performs insufficient validation of the request_uri parameter. An attacker can craft a request containing an invalid request_uri paired with an unvalidated redirect_uri, which can result in an open redirect to an attacker-controlled site. | |
| Title | Spring Authorization Server: Open Redirect via request_uri parameter | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-08-27T06:35:09.607Z
Reserved: 2026-07-04T18:14:46.172Z
Link: CVE-2026-59355
Updated: 2026-08-27T13:37:25.394Z
Status : Received
Published: 2026-08-27T10:16:36.197
Modified: 2026-08-27T10:16:36.197
Link: CVE-2026-59355
No data.
OpenCVE Enrichment
Updated: 2026-08-27T10:30:06Z