CVE-2026-22742: Server-Side Request Forgery in BedrockProxyChatModel via Unvalidated Media URL Fetching
Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to induce the server to issue HTTP requests to unintended internal or external destinations. This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22742?
CVE-2026-22742 is considered a high-severity vulnerability due to its potential for Server-Side Request Forgery (SSRF) attacks.
How do I fix CVE-2026-22742?
To fix CVE-2026-22742, update the spring-ai-bedrock-converse library to version 1.0.6 or later, or version 1.1.5 or later.
What software is affected by CVE-2026-22742?
CVE-2026-22742 affects the spring-ai-bedrock-converse library versions between 1.0.0 and 1.0.5, and 1.1.0 and 1.1.4.
What type of vulnerability is CVE-2026-22742?
CVE-2026-22742 is a Server-Side Request Forgery (SSRF) vulnerability that allows unvalidated media URL fetching.
What are the potential impacts of CVE-2026-22742?
The potential impacts of CVE-2026-22742 include unauthorized access to internal services and exposure of sensitive data.