Input validation error in Spring Framework - CVE-2026-41854
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform server-side request forgery.
The vulnerability exists due to incorrect host parsing in uricomponentsbuilder when parsing and validating an externally provided URL string. A remote attacker can supply a crafted URL string to perform server-side request forgery.
User interaction is required.