Server-Side Request Forgery Vulnerability in Spring Framework
CVE-2026-41854

4.2MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41854?

A vulnerability has been identified in the Spring Framework due to improper host parsing, which can lead to server-side request forgery (SSRF) attacks. Applications that utilize UriComponentsBuilder for the parsing and validation of externally provided URL strings are particularly susceptible. Attackers could exploit this flaw to redirect requests to internal services, potentially compromising sensitive data and infrastructure. It is crucial for users of affected versions to apply the necessary patches that have been made available.

Affected Version(s)

Spring Framework 7.0.0 < 7.0.7.1

Spring Framework 6.2.0 < 6.2.18.1

References

CVSS V3.1

Score:
4.2
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.