Medium severity4.2NVD Advisory· Published Jun 9, 2026· Updated Jun 15, 2026
CVE-2026-41854
CVE-2026-41854
Description
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.
Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework:spring-webMaven | >= 7.0.0, < 7.0.8 | 7.0.8 |
org.springframework:spring-webMaven | >= 6.2.0, < 6.2.19 | 6.2.19 |
Affected products
2- Range: >=7.0.0 <=7.0.7, >=6.2.0 <=6.2.18
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-7m2p-62gw-p8qqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-41854ghsaADVISORY
- spring.io/security/cve-2026-41854nvdVendor AdvisoryWEB
News mentions
0No linked articles in our index yet.