CVE-2026-22742 is a Server-Side Request Forgery (SSRF) vulnerability in Spring AI's spring-ai-bedrock-converse, specifically affecting the BedrockProxyChatModel. This flaw, present in versions 1.0.0 before 1.0.5 and 1.1.0 before 1.1.4, arises from insufficient validation of user-supplied media URLs in multimodal messages. With a CVSS score of 8.6 (HIGH), an unauthenticated attacker can remotely induce the server to make HTTP requests to unintended internal or external destinations, potentially leading to information disclosure. The attack requires no user interaction or privileges and has low complexity. There is currently no evidence of active exploitation, public exploit code, or widespread community attention, and it is not listed on the CISA KEV or Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.0, < 1.0.5CPE matchmatch criteria | cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:* | ||
>= 1.1.0, < 1.1.4CPE matchmatch criteria | cpe:2.3:a:vmware:spring_ai:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.