CVE-2026-22742
March 27, 2026
Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing multimodal messages that include user-supplied media URLs. Insufficient validation of those URLs allows an attacker to induce the server to issue HTTP requests to unintended internal or external destinations.
This issue affects Spring AI: from 1.0.0 before 1.0.5, from 1.1.0 before 1.1.4.
Affected Packages
org.springframework.ai:spring-ai-bedrock-converse (JAVA):
Affected version(s) >=1.1.0 <1.1.4Fix Suggestion:
Update to version 1.1.4org.springframework.ai:spring-ai-bedrock-converse (JAVA):
Affected version(s) >=1.0.0 <1.0.5Fix Suggestion:
Update to version 1.0.5org.springframework.ai:spring-ai-bedrock-converse (JAVA):
Affected version(s) >=1.0.0 <1.0.5Fix Suggestion:
Update to version 1.0.5org.springframework.ai:spring-ai-bedrock-converse (JAVA):
Affected version(s) >=1.0.0 <1.0.5Fix Suggestion:
Update to version 1.0.5org.springframework.ai:spring-ai-bedrock-converse (JAVA):
Affected version(s) >=1.1.0 <1.1.4Fix Suggestion:
Update to version 1.1.4org.springframework.ai:spring-ai-bedrock-converse (JAVA):
Affected version(s) >=1.0.0 <1.0.5Fix Suggestion:
Update to version 1.0.5org.springframework.ai:spring-ai-bedrock-converse (JAVA):
Affected version(s) >=1.0.0 <1.0.5Fix Suggestion:
Update to version 1.0.5org.springframework.ai:spring-ai-bedrock-converse (JAVA):
Affected version(s) >=1.1.0 <1.1.4Fix Suggestion:
Update to version 1.1.4org.springframework.ai:spring-ai-bedrock-converse (JAVA):
Affected version(s) >=1.1.0 <1.1.4Fix Suggestion:
Update to version 1.1.4org.springframework.ai:spring-ai-bedrock-converse (JAVA):
Affected version(s) >=1.1.0 <1.1.4Fix Suggestion:
Update to version 1.1.4Related Resources (6)
Do you need more information?
Contact UsCVSS v3
Base Score:
8.6
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE
Weakness Type (CWE)
Server-Side Request Forgery (SSRF)
EPSS
Base Score:
0.03