Spring Framework Security Filter Bypass in WebFlux Kotlin Router DSL
CVE-2026-41847
4.8MEDIUM
What is CVE-2026-41847?
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.
Affected versions: Spring Framework 5.3.0 through 5.3.48.
Affected Version(s)
Spring Framework 5.3.0 < 5.3.49
