Back

MEDIUM

Spring Framework Server-Side Request Forgery via UriComponentsBuilder

Published Jun 9, 2026

Description

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.

Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.

Affected products

Remediation

Red Hat statement

A flaw was found in Spring Framework. Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. This flaw only affects Spring Framework versions 6.2.0 through 6.2.18 and 7.0.0 through 7.0.7.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Metrics

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Jun 9, 2026
Updated Jun 27, 2026
Reserved Apr 22, 2026
CISA Vulnrichment
Updated Jun 9, 2026
NVD
Status Analyzed
Modified Jul 23, 2026
Red Hat
Severity Moderate
Public date Jun 9, 2026
GHSA-7M2P-62GW-P8QQ