CVE-2026-7605: JeecgBoot uploadImgByHttpEndpoint CommonController.java HttpFileToMultipartFileUtil.downloadImageData server-side request forgery
A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.uploadImgByHttp/HttpFileToMultipartFileUtil.httpFileToMultipartFile/HttpFileToMultipartFileUtil.downloadImageData of the file CommonController.java of the component uploadImgByHttpEndpoint. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Upgrading the affected component is recommended. The vendor confirmed the issue and will provide a fix in the upcoming release.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7605?
CVE-2026-7605 is classified as a server-side request forgery (SSRF) vulnerability that could lead to unauthorized access to internal resources.
How do I fix CVE-2026-7605?
To fix CVE-2026-7605, upgrade JeecgBoot to version 3.9.2 or later, which addresses the vulnerability.
What products are affected by CVE-2026-7605?
CVE-2026-7605 affects JeecgBoot versions up to and including 3.9.1.
What are the potential impacts of CVE-2026-7605?
The potential impacts of CVE-2026-7605 include the ability for attackers to perform unauthorized actions on internal services through crafted requests.
Who should be concerned about CVE-2026-7605?
Organizations using JeecgBoot version 3.9.1 or earlier should be concerned about CVE-2026-7605 due to the security risks it poses.