Feed/CVE-2026-41854
CVE-2026-41854MEDIUMCVSS 4.2

CVE-2026-41854

Published Jun 9, 2026·Updated Aug 6, 2026

NVD Description

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack. Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.

Affected Packages (1)

org.springframework:spring-webMAVEN
From 7.0.0
Fixed in = 7.0.7

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free