Executive brief
Spring Boot Admin Server, a tool used to manage and monitor Spring Boot applications, is vulnerable to a security flaw that allows unauthorized attackers to trick the server into making internal network requests. By registering a malicious application instance, an attacker can force the server to connect to internal systems or cloud metadata services that are not normally accessible from the outside. This can lead to the theft of sensitive cloud credentials or the exposure of private internal data, potentially compromising the entire cloud environment.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in Spring Boot Admin (SBA) Server due to insufficient validation of the 'healthUrl' and 'managementUrl' parameters during instance registration. An unauthenticated attacker can submit a POST request to the /instances endpoint to register a malicious instance pointing to internal IP addresses, loopback interfaces, or cloud metadata endpoints (e.g., AWS IMDSv1). The server's StatusUpdater and EndpointDetector components automatically initiate outbound GET requests to these URLs. Furthermore, the InstancesProxyController forwards requests to these URLs via the /instances/{id}/actuator/** proxy, allowing attackers to retrieve full response bodies, including sensitive IAM credentials or internal API data. The fix in version 4.1.2 introduces an opt-in SSRF protection mechanism to validate URLs against allowed CIDR ranges and schemes.
Affected products
- codecentric Spring Boot Admin Server < 4.1.2
Timeline
- 2026-06-16: disclosed: Issue reported on GitHub
- 2026-07-11: patched: Fix merged into master branch
- 2026-07-13: advisory: CVE published to NVD
References
- https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551
- https://github.com/codecentric/spring-boot-admin/issues/5452
- https://github.com/codecentric/spring-boot-admin/pull/5464
- https://github.com/codecentric/spring-boot-admin/releases/tag/4.1.2
- https://www.vulncheck.com/advisories/spring-boot-admin-server-ssrf-via-unauthenticated-instance-registration