Server-side Request Forgery (SSRF) Affecting de.codecentric:spring-boot-admin-server package, versions [,4.1.2)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

Exploit Maturity
Proof of Concept
EPSS
0.28% (21st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-DECODECENTRIC-17962534
  • published14 Jul 2026
  • disclosed13 Jul 2026
  • creditUnknown

Introduced: 13 Jul 2026

NewCVE-2026-62242  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade de.codecentric:spring-boot-admin-server to version 4.1.2 or higher.

Overview

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) through the instance registration and proxy handling in InstanceRegistry and InstanceWebProxy. An attacker can make the server send outbound HTTP requests to arbitrary internal addresses and exfiltrate response bodies by registering an instance with attacker-controlled healthUrl, managementUrl, or serviceUrl values and then using the actuator proxy. This lets an unauthenticated attacker reach loopback, private network, and cloud metadata endpoints from the Admin Server’s network context, exposing sensitive data such as instance-local secrets or cloud credentials. The user’s Admin Server can be used as a relay to probe internal services and leak the responses through its management endpoints.

CVSS Base Scores

version 4.0
version 3.1