Medium severity4.2NVD Advisory· Published Jun 9, 2026· Updated Jun 15, 2026
CVE-2026-41854
CVE-2026-41854
Description
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: >=7.0.0 <=7.0.7, >=6.2.0 <=6.2.18
Patches
Vulnerability mechanics
References
1- spring.io/security/cve-2026-41854nvdVendor Advisory
News mentions
0No linked articles in our index yet.