A WebFlux application running on the Jetty 12 Core reactive adapter serializes response cookies without the sameSite attribute. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-47889 affects Spring Framework versions 6.2.0-6.2.19 and 7.0.0-7.0.8, where WebFlux applications running on Jetty 12 Core serialize response cookies without the sameSite attribute. This omission creates a cross-site request forgery (CSRF) vulnerability, allowing attackers to bypass same-site cookie protections that modern browsers enforce. Organizations running affected Spring Framework versions in production environments are at risk, particularly those handling sensitive operations through web applications where session hijacking or unauthorized state-changing requests could occur. The vulnerability has a CVSS score of 7.5 (high), reflecting its significant impact on application security posture.
While Casky's current skill library shows 0 direct matches for this CVE, practitioners using Casky's Claude-powered analysis would detect attack patterns associated with cookie manipulation and session-based attacks mapped to MITRE ATT&CK techniques like T1539 (Steal Web Session Cookie) and T1548 (Abuse Elevation Control Mechanism). Security teams examining logs from affected applications would identify suspicious cross-origin requests that successfully modify state, anomalous session activity patterns, or failed CSRF token validations. By running extended reasoning against the 754 mapped security skills, Casky would help practitioners correlate these observations with the underlying cookie serialization issue, guiding them toward patching Spring Framework to versions 6.2.20+ or 7.0.9+ and implementing explicit sameSite=Strict configurations as interim mitigations.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-47889. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation