Server-side Request Forgery (SSRF) Affecting org.springframework:spring-web package, versions [6.2.0, 6.2.19)[7.0.0-M1, 7.0.8)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.12% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGSPRINGFRAMEWORK-17254521
  • published9 Jun 2026
  • disclosed8 Jun 2026
  • creditFushuling@secsys, RacerZ@secsys

Introduced: 8 Jun 2026

CVE-2026-41854  (opens in a new tab)
CWE-918  (opens in a new tab)

How to fix?

Upgrade org.springframework:spring-web to version 6.2.19, 7.0.8 or higher.

Overview

org.springframework:spring-web is a package that provides a comprehensive programming and configuration model for modern Java-based enterprise applications - on any kind of deployment platform.

Affected versions of this package are vulnerable to Server-side Request Forgery (SSRF) via incorrect host parsing in UriComponentsBuilder. An attacker can perform server-side request forgery by supplying a crafted URL that is interpreted differently than intended during validation, allowing requests to be sent to unintended hosts despite application-level hostname validation checks.

CVSS Base Scores

version 4.0
version 3.1