CVE-2026-11477

medium

Description

A vulnerability was detected in hs-web hsweb-framework up to 5.0.1. This affects the function OAuth2Client of the file hsweb-authorization/hsweb-authorization-oauth2/src/main/java/org/hswebframework/web/oauth2/server/OAuth2Client.java of the component OAuth2 Client. The manipulation results in open redirect. The attack can be executed remotely. The exploit is now public and may be used. The patch is identified as c2882679a9125cea52678151af5ae213cbd52579. Applying a patch is advised to resolve this issue.

References

https://vuldb.com/vuln/369097/cti

https://vuldb.com/vuln/369097

https://vuldb.com/submit/833962

https://vuldb.com/cve/CVE-2026-11477

https://github.com/hs-web/hsweb-framework/pull/355

https://github.com/hs-web/hsweb-framework/issues/354

https://github.com/hs-web/hsweb-framework/commit/c2882679a9125cea52678151af5ae213cbd52579

https://github.com/hs-web/hsweb-framework/

Details

Source: Mitre, NVD

Published: 2026-06-08

Updated: 2026-06-08

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.00032