Spring Framework Server-Side Request Forgery via UriComponentsBuilder
Moderate severity
GitHub Reviewed
Published
Jun 9, 2026
to the GitHub Advisory Database
•
Updated Aug 6, 2026
Package
Affected versions
>= 7.0.0, <= 7.0.7
>= 6.2.0, <= 6.2.18
Patched versions
7.0.8
6.2.19
Description
Published by the National Vulnerability Database
Jun 9, 2026
Published to the GitHub Advisory Database
Jun 9, 2026
Reviewed
Aug 6, 2026
Last updated
Aug 6, 2026
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
References