{"id":"CVE-2026-62242","summary":"Spring Boot Admin Server \u003c 4.1.2 SSRF via Unauthenticated Instance Registration","details":"Spring Boot Admin Server before 4.1.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers to register instances with attacker-controlled healthUrl and managementUrl parameters without validation against private IP ranges or metadata endpoints. Attackers can force the server to make HTTP requests to arbitrary internal addresses and retrieve response bodies via the actuator proxy to exfiltrate cloud credentials.","modified":"2026-07-22T03:49:49.635793Z","published":"2026-07-13T21:04:26.002Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62242.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/62xxx/CVE-2026-62242.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-62242"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/spring-boot-admin-server-ssrf-via-unauthenticated-instance-registration"},{"type":"REPORT","url":"https://github.com/codecentric/spring-boot-admin/issues/5452"},{"type":"FIX","url":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551"},{"type":"FIX","url":"https://github.com/codecentric/spring-boot-admin/pull/5464"},{"type":"FIX","url":"https://github.com/codecentric/spring-boot-admin/releases/tag/4.1.2"},{"type":"PACKAGE","url":"https://github.com/codecentric/spring-boot-admin"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/codecentric/spring-boot-admin","events":[{"introduced":"0"},{"fixed":"9dd5a52bcbb52a84db964bcc44404a996dcae42a"},{"fixed":"1f991ea013e46360b8f8fb63fe4ad20a9bf0d551"}],"database_specific":{"source":["DESCRIPTION","REFERENCES"],"extracted_events":[{"introduced":"0"},{"fixed":"4.1.2"}]}}],"versions":["4.1.1","4.1.0","4.0.4","4.0.3","3.5.8","4.0.2","4.0.1","4.0.0","4.0.0-M2","4.0.0-M1","3.5.7","3.5.6","3.5.5","3.5.4","3.5.3","3.5.2","3.5.1","3.5.0","3.4.7","3.4.6","3.4.5","3.4.4","3.4.3","3.4.2","3.4.1","3.4.0","3.3.6","3.3.5","3.3.4","3.3.3","3.3.2","3.2.3","3.2.2","3.2.1","3.2.0","3.1.8","3.1.7","2.7.2","3.1.6","3.1.5","3.1.4","3.1.3","3.1.2","3.1.1","3.1.0","3.0.4","3.0.3","3.0.2","3.0.1","3.0.0","3.0.0-M9","2.7.10","2.7.9","2.7.8","2.7.7","2.7.6","2.7.5","2.7.4","2.7.3","2.6.7","2.7.1","2.7.0","2.6.6","2.6.5","2.5.5","2.6.3","2.6.2","2.6.1","2.6.0","2.5.4","2.5.3","2.5.2","2.4.3","2.5.1","2.5.0","2.4.2","2.4.1","2.4.0","2.3.1","2.3.0","2.2.3","2.2.2","2.2.1","2.2.0","2.1.3","2.1.2","2.1.1","2.1.0","2.0.2","2.0.1","2.0.0","1.5.7","1.5.6","1.5.5","1.5.4","1.5.3","1.5.2","1.5.1","1.5.0","1.4.3","1.4.2","1.4.1","1.4.0","1.3.3","1.3.2","1.3.1","1.3.0","1.2.4","1.2.3","1.2.2","1.2.1","1.2.0","1.1.2","1.1.1","1.1.0","1.0.4","1.0.3"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-62242.json","vanir_signatures_modified":"2026-07-22T03:49:49Z","vanir_signatures":[{"id":"CVE-2026-62242-07c1835b","signature_type":"Function","signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/web/InstanceWebProxy.java","function":"forward"},"deprecated":false,"digest":{"function_hash":"100008158505966104599558899699317286183","length":1549}},{"source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"file":"spring-boot-admin-server/src/test/java/de/codecentric/boot/admin/server/config/AdminServerAutoConfigurationTest.java"},"deprecated":false,"digest":{"line_hashes":["156807855656958698171235649337913906187","270838767986119867886735812925272489446","298735637266917699748064086043692518613","157904818514332621965444072892854701711","27046840684872047152568093448697712588","199723355324604075796137214166161105203","62341110682621468331407118880163018524","196319398605161519165889265483233403137","2624429937921593366315652745942692167","186986548410392592753902430694764963966","175692739725654050782389204128497045962"],"threshold":0.9},"id":"CVE-2026-62242-320102cb","signature_type":"Line","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"file":"spring-boot-admin-server/src/test/java/de/codecentric/boot/admin/server/services/InstanceRegistryTest.java"},"deprecated":false,"digest":{"line_hashes":["189713421974127258591355058906184946863","124824370550437668929618284440543413506","203706561420230900135017323640015702082","18059411042215139593416027072581195081","291641272486937831686260900444013198020","36162281519578361906714038486333446328","119656589220638375720444491804937496219","174199157830371089746736898785213432801","93423630680441014342980865872027710591","101720359671769726547645355338597841057","104232489883745307587192016567936467623"],"threshold":0.9},"id":"CVE-2026-62242-338f37c2","signature_type":"Line"},{"signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/services/InstanceRegistry.java"},"deprecated":false,"digest":{"line_hashes":["202854208713121513948579885286457809570","302631851368220094435809647907454511375","258388010722351975065368860749196711847","293310809775149890235364650216185596111","309849046514927195074470251578352400813","141998448740872802504956800940531849906","328550309124169599396490466839341107077","82398581451911866581744020512995468335","207829597099580924051406089594662001793","140495323055610596251524851247084520024","3520433830034456004512797251889390475","244652159838072326703294578418757966980","144288409025122597399869710302696183314","247190618680270792271434102468854832043","146099634602567431536336618280330275094","230778333744182466370342626140139319110","123756412058512999731631826479351279790","80484682730820766774597190177178118962"],"threshold":0.9},"id":"CVE-2026-62242-351c94dc","signature_type":"Line"},{"deprecated":false,"digest":{"line_hashes":["105678076610850471334568919470845279314","17180694634293486720744332125502406169","59919655077496503119243538622009109631","40342207496959965431696371029012119440","128832033368376731957470524280104951011","333042140726474938146875701027069965521","116301959053887298785375949279702225880","318134666783965325762659466306770399560","48373388412475284680089234102460533547"],"threshold":0.9},"id":"CVE-2026-62242-3758857b","signature_type":"Line","signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/config/AdminServerProperties.java"}},{"digest":{"threshold":0.9,"line_hashes":["222793423023417388148033967927212178945","323604598396191047487333735594778155087","254226653538515448225802959323207908930","1444283035809988469330484218221521298","4754819529772290374934119591921694708","54643681452091667356220893604908338055","286668357385245142784084635478118846672","139096374558441102848310903711896215943","181617341840269487266998236782728988276","320277199619269884100409658982934465005","84370948446220144730436006273990638230","304147019210547091926195854730556093685","258873213876054234872651992573861345291","186754828581073858413386310292942094572","154587578882727199229173062321495649691","22060312588866988950064154742656339638"]},"id":"CVE-2026-62242-54451310","signature_type":"Line","signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/web/InstanceWebProxy.java"},"deprecated":false},{"id":"CVE-2026-62242-68a2302b","signature_type":"Function","signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/web/reactive/InstancesProxyController.java","function":"InstancesProxyController"},"deprecated":false,"digest":{"function_hash":"304689020852368213052135489015326919883","length":219}},{"deprecated":false,"digest":{"line_hashes":["200262950409325677854645194460726064494","46454900578894499443792902464674447228","67357823357945700199764170159891592400","216530467349796404816047903603972354515","170403850729465745939052611267582783717","274671931816159654129304059355511994334","151515583248940181106657196011531394467","172726812854308012694830559769209533722","56822026661528239968160938053024754312","139290092027628999870675803916883814645","226795821931889797876911830104891157026","210953598263599814830570691141839223051","289160668828022040920805623236753572885","317636585966401622455797671679497387927","101851846162999029912561793526475784902","55238472990681299365781730680369930709","279015644184347394693257874002726639394","126338782677581622598984981451247732785","226795821931889797876911830104891157026","210953598263599814830570691141839223051","257294207787978629681177114562460874413"],"threshold":0.9},"id":"CVE-2026-62242-6fe6e996","signature_type":"Line","signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/config/AdminServerWebConfiguration.java"}},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"function":"InstanceRegistry","file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/services/InstanceRegistry.java"},"deprecated":false,"digest":{"function_hash":"276849226725221505050513190310608889350","length":125},"id":"CVE-2026-62242-7ca36615"},{"digest":{"function_hash":"304689020852368213052135489015326919883","length":219},"id":"CVE-2026-62242-89671e14","signature_type":"Function","signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/web/servlet/InstancesProxyController.java","function":"InstancesProxyController"},"deprecated":false},{"deprecated":false,"digest":{"function_hash":"15794568751178796263381488546088436171","length":207},"id":"CVE-2026-62242-a40d0a0c","signature_type":"Function","signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/config/AdminServerWebConfiguration.java","function":"instancesProxyController"}},{"source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/web/servlet/InstancesProxyController.java"},"deprecated":false,"digest":{"line_hashes":["124092355772615738631902248674076019420","316520656236376887949482477467951085031","179342738101793232364480165200557025962","178819255270615956289571761919267243641","326429425834114207703277669236751747514","303950782669319741956541225765578441363","88314709108235550039983988279692473262","208878491555500096760834225135399640469","88564305371389897579451995283295443606","145259178728592728066155878980319513819","122255522459023118341065876818496127627","89170827453476387710570667637966247537","10771600309321985972322703915637848708"],"threshold":0.9},"id":"CVE-2026-62242-a49778fa","signature_type":"Line","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"15794568751178796263381488546088436171","length":207},"id":"CVE-2026-62242-c9bc9d7b","signature_type":"Function","signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"function":"instancesProxyController","file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/config/AdminServerWebConfiguration.java"}},{"signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/web/reactive/InstancesProxyController.java"},"deprecated":false,"digest":{"line_hashes":["240302086261644377507795054115959953999","316520656236376887949482477467951085031","179342738101793232364480165200557025962","178819255270615956289571761919267243641","326429425834114207703277669236751747514","287011586423115955375503375309538688641","182965173079515638853453081697500670274","208878491555500096760834225135399640469","88564305371389897579451995283295443606","145259178728592728066155878980319513819","122255522459023118341065876818496127627","22154421325061091762442680253493975252","84890354723345860564652248872419711584"],"threshold":0.9},"id":"CVE-2026-62242-cc431850","signature_type":"Line"},{"deprecated":false,"digest":{"function_hash":"84772439047380298415693758249713984207","length":427},"id":"CVE-2026-62242-cd3666af","signature_type":"Function","signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551","target":{"file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/services/InstanceRegistry.java","function":"register"}},{"target":{"file":"spring-boot-admin-server/src/main/java/de/codecentric/boot/admin/server/config/AdminServerAutoConfiguration.java"},"deprecated":false,"digest":{"line_hashes":["21776350266466919101954010040482153227","231847383424287581306350302267283971121","225679504980433026555928173601793168069","65950188101075963626962859006745682966","217220006500138264917733147317949506664","242486245128322619360493511301646566827","237177480802496336372346548738067832833","115032454132869659363731065578253721837","245620457220629839293019251972537253418","54215546426341557834537759820768409559","316625207290273125515136251209033549812","16438302844652666128210806568981754008","232442685158489917432244440344309594849","201147103847711643288431370644709906340","157614541848746214179662290020322222707","221612658846992087686008654586229136854","238485513006486773567775069395049026836","91270176634386897881395570218261869943","195229567413783850641861047327199742632","334832790552280479821746512304063674417","128051009676263062824056460155685414075","185632816789265401230578813876286309368","92517843774163481506986688468633840133","75987734103979700324876622979717137506"],"threshold":0.9},"id":"CVE-2026-62242-d8077617","signature_type":"Line","signature_version":"v1","source":"https://github.com/codecentric/spring-boot-admin/commit/1f991ea013e46360b8f8fb63fe4ad20a9bf0d551"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N"}]}