GHSA-7m2p-62gw-p8qq

Suggest an improvement
Source
https://github.com/advisories/GHSA-7m2p-62gw-p8qq
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-7m2p-62gw-p8qq/GHSA-7m2p-62gw-p8qq.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7m2p-62gw-p8qq
Aliases
  • CVE-2026-41854
Downstream
Published
2026-06-09T06:31:58Z
Modified
2026-08-06T19:30:55.384213955Z
Severity
  • 4.2 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:N CVSS Calculator
Summary
Spring Framework Server-Side Request Forgery via UriComponentsBuilder
Details

Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.

Affected versions: Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18.

Database specific
{
    "github_reviewed_at": "2026-08-06T19:11:45Z",
    "nvd_published_at": "2026-06-09T05:16:37Z",
    "cwe_ids": [
        "CWE-918"
    ],
    "github_reviewed": true,
    "severity": "MODERATE"
}
References

Affected packages

Maven / org.springframework:spring-web

Package

Name
org.springframework:spring-web
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-web

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.0
Fixed
7.0.8

Affected versions

7.*
7.0.0
7.0.1
7.0.2
7.0.3
7.0.4
7.0.5
7.0.6
7.0.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-7m2p-62gw-p8qq/GHSA-7m2p-62gw-p8qq.json"
last_known_affected_version_range
"<= 7.0.7"

Maven / org.springframework:spring-web

Package

Name
org.springframework:spring-web
View open source insights on deps.dev
Purl
pkg:maven/org.springframework/spring-web

Affected ranges

Type
ECOSYSTEM
Events
Introduced
6.2.0
Fixed
6.2.19

Affected versions

6.*
6.2.0
6.2.1
6.2.2
6.2.3
6.2.4
6.2.5
6.2.6
6.2.7
6.2.8
6.2.9
6.2.10
6.2.11
6.2.12
6.2.13
6.2.14
6.2.15
6.2.16
6.2.17
6.2.18

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-7m2p-62gw-p8qq/GHSA-7m2p-62gw-p8qq.json"
last_known_affected_version_range
"<= 6.2.18"