Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.

Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Tue, 09 Jun 2026 04:45:00 +0000

Type Values Removed Values Added
Description Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
Title Spring Framework Server-Side Request Forgery via UriComponentsBuilder
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-06-09T03:51:49.021Z

Reserved: 2026-04-22T06:22:10.081Z

Link: CVE-2026-41854

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-09T05:16:37.647

Modified: 2026-06-09T05:16:37.647

Link: CVE-2026-41854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses