Junglewise Threat Intelligence

CVE-2026-22742: Spring AI's spring-ai-bedrock-converse contains a Server-Side Request Forgery (SSRF) vulnerability in BedrockProxyChatModel when processing

CVE-2026-22742 · Severity: high · CVSS 8.6 · Published 2026-03-27

Technologies: VMware Spring Ai. Vendors: VMware.

Executive brief

Spring AI is a framework used by developers to integrate artificial intelligence capabilities into Java applications. A security flaw in its Amazon Bedrock integration allows attackers to force the application to make unauthorized network requests. This could lead to the exposure of sensitive internal data or allow attackers to bypass firewalls to reach private internal services.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the BedrockProxyChatModel component of Spring AI. The vulnerability is rooted in the insufficient validation of user-supplied media URLs within multimodal messages. A remote, unauthenticated attacker can exploit this by providing a specially crafted URL, causing the server to initiate outbound HTTP requests to arbitrary internal or external IP addresses. This can be used to scan internal networks, access metadata services, or pivot to other internal resources. The issue is fixed in Spring AI versions 1.0.5 and 1.1.4.

Affected products

  • VMware Spring AI 1.0.0 to 1.0.4, 1.1.0 to 1.1.3

Timeline

  • 2026-03-27: advisory: Initial advisory published by VMware and NVD

References