Back

HIGH

Spring Framework sameSite Attribute Dropped in JettyCoreServerHttpResponse

Published Aug 27, 2026

Description

A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Aug 27, 2026
Updated Aug 27, 2026
Reserved May 20, 2026
CISA Vulnrichment
Updated Aug 27, 2026
NVD
Status Analyzed
Modified Sep 10, 2026
Red Hat
Severity n/a
Public date n/a