CVE-2024-22262: Spring Framework

High severity, CVSS 8.1. EPSS: 1.2% chance of exploitation in the next 30 days.

Applications that use UriComponentsBuilder to parse an externally provided URL (e.g. through a query parameter) AND perform validation checks on the host of the parsed URL may be vulnerable to a open redirect https://cwe.mitre.org/data/definitions/601.html  attack or to a SSRF attack if the URL is used after passing validation checks. This is the same as CVE-2024-22259 https://spring.io/security/cve-2024-22259  and CVE-2024-22243 https://spring.io/security/cve-2024-22243 , but with different input.

Affected products

  • Spring Spring Framework: from 6.1, before 6.1.6 (fixed in 6.1.6); from 6.0, before 6.0.19 (fixed in 6.0.19); from 5.3, before 5.3.34 (fixed in 5.3.34)
  • VMware Spring Framework: from 6.1.0, before 6.1.6 (fixed in 6.1.6); from 6.0.0, before 6.0.19 (fixed in 6.0.19); from 5.3.0, before 5.3.34 (fixed in 5.3.34)

Published 2024-04-16. Last modified 2026-06-17.