Package
conductor
Component
spring-webflux
Latest update
9.8
CVSS V3
Build, ship, and run secure software with minimal, hardened container images — rebuilt from source daily and guarded under our industry-leading remediation SLA.
Start for freeStatus
Justification
Impact
CVE-2026-47892 affects only WebFlux functional endpoints (RouterFunction and RequestPredicates header predicates) served through DispatcherServlet. The application is a Spring MVC servlet application whose endpoints are all annotation-based controllers, and no application or bundled-library class defines or registers a functional endpoint. The only references are Spring Boot actuator, autoconfigure and springdoc introspection code. The vulnerable code path is therefore never executed.
Status