CVE-2026-47889CWE-1275
CVE-2026-47889
High · published August 27, 2026
What it is
A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute.
Spring Framework 7.0.0 - 7.0.8
Spring Framework 6.2.0 - 6.2.19
The record
Technical detail
- CVSS v3.1
- 7.5 · HIGH
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- CVSS v4.0
- Not supplied
- EPSS
- 0.00253 · 16.6th percentile
- Weakness
- CWE-1275 · Sensitive Cookie with Improper SameSite Attribute
- Published
- 2026-08-27T10:17Z
References (1)
EPSS history
Timeline