Executive brief
Spring Framework, a widely-used Java application framework, contains a vulnerability in its XsltView component that can allow attackers to perform Server-Side Request Forgery (SSRF) and Remote Code Execution (RCE) attacks. Applications using wildcard URL mappings combined with automatic view rendering are at risk. An attacker can exploit this to access internal resources, bypass network controls, or execute arbitrary code on the affected server.
Technical details
This vulnerability exists in Spring Framework's XsltView when applications configure a "/**" path mapping that results in automatic view rendering without explicit view name specification. The vulnerable component fails to properly validate or sanitize user-controlled view names, enabling both SSRF attacks (allowing the attacker to make requests to arbitrary internal or external URLs) and RCE through malicious XSLT stylesheets. The attack is network-accessible and does not require authentication. Affected versions include Spring Framework 5.2.25.RELEASE and earlier, 5.3.0–5.3.49, 6.0.0–6.0.30, 6.1.0–6.1.28, 6.2.0–6.2.19, and 7.0.0–7.0.8. Patches are available in patched versions outside these ranges.
Affected products
- Spring Spring Framework 5.2.25.RELEASE and earlier, 5.3.0–5.3.49, 6.0.0–6.0.30, 6.1.0–6.1.28, 6.2.0–6.2.19, 7.0.0–7.0.8
Timeline
- 2026-08-27: disclosed