CVE-2026-41854
published 2026-06-09CVE-2026-41854: Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a…
PriorityP335medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
0.12%
2.5th percentile
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_framework | >= 6.2.0 < 6.2.18.1 | 6.2.18.1 |
| spring | spring_framework | >= 7.0.0 < 7.0.7.1 | 7.0.7.1 |
| vmware | spring_framework | >= 6.2.0 < 6.2.18.1 | 6.2.18.1 |
| vmware | spring_framework | >= 7.0.0 < 7.0.7.1 | 7.0.7.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Vmware Spring Framework up to 6.2.18/7.0.7 UriComponentsBuilder server-side request forgery
vuldb·2026-06-15·CVSS 6.5
CVE-2026-41854 [MEDIUM] Vmware Spring Framework up to 6.2.18/7.0.7 UriComponentsBuilder server-side request forgery
A vulnerability was found in Vmware Spring Framework up to 6.2.18/7.0.7. It has been declared as critical. This affects an unknown function of the component UriComponentsBuilder. Such manipulation leads to server-side request forgery.
This vulnerability is referenced as CVE-2026-41854. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
GHSA
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.
ghsa_unreviewed·2026-06-09
CVE-2026-41854 [MEDIUM] CWE-918 Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
Red Hat
spring-framework: Spring Framework: Server-Side Request Forgery via incorrect host parsing
vendor_redhat·2026-06-09·CVSS 6.5
CVE-2026-41854 [MEDIUM] CWE-918 spring-framework: Spring Framework: Server-Side Request Forgery via incorrect host parsing
spring-framework: Spring Framework: Server-Side Request Forgery via incorrect host parsing
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
A flaw was found in Spring Framework. Due to incorrect host parsing in the UriComponentsBuilder component, applications that process externally provided URL strings may be vulnerable to a Server-Side Request Forgery (SSRF) attack. An SSRF attack allows an attacker to trick the server into making requests to an arbitrary domain, potentially leading to information disclosure or unauthorized actions.
Statement: A flaw was found i
No detection rules found.
No public exploits indexed.
2026-06-09
Published