CVE-2026-47889CWE-1275

CVE-2026-47889

High · published August 27, 2026

CVSS v3.1
7.5
EPSS
0%
Percentile
16.6
In the wild
Unconfirmed
What it is

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute.

Spring Framework 7.0.0 - 7.0.8

Spring Framework 6.2.0 - 6.2.19

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00253 · 16.6th percentile
Weakness
CWE-1275 · Sensitive Cookie with Improper SameSite Attribute
Published
2026-08-27T10:17Z
References (1)
EPSS history
Timeline
  • 28 AUG 06:43Z
    EPSS moved — → 0%
    epss
  • 27 AUG 05:21Z
    Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse
    cvelistv5