Spring Boot 4.1.0 introduced InetAddressFilter, which lets HTTP clients restrict outgoing requests by destination IP address. For a single client, attach a filter through HttpClientSettings; for auto-configured client builders, define an InetAddressFilter bean. This is a useful SSRF control, but it does not replace URL validation, redirect checks, or review of every outbound client path.
Which Spring Boot versions support InetAddressFilter?
Spring announced the feature with Spring Boot 4.1.0 on June 10, 2026. The configuration examples are in the Spring Boot 4.1 reference, and the API documentation cited here is for Spring Boot 4.1.1. Do not assume the feature is available in earlier Spring Boot versions based on these references. Spring’s 4.1.0 release announcement identifies the release, while the Spring Boot 4.1 REST client reference describes its configuration for blocking and reactive clients.
As an Amazon Associate I earn from qualifying purchases.
Configure a filter for one RestClient
To apply the broad built-in external-address policy to a particular JDK-backed RestClient, pass the filter to HttpClientSettings when building the request factory:
Recommended Free Tools
InetAddressFilter onlyExternalAddresses = InetAddressFilter.externalAddresses();
HttpClientSettings settings = HttpClientSettings.defaults()
.withInetAddressFilter(onlyExternalAddresses);
ClientHttpRequestFactory requestFactory = ClientHttpRequestFactoryBuilder.jdk()
.build(settings);
RestClient restClient = RestClient.builder()
.requestFactory(requestFactory)
.baseUrl("https://example.org")
.build();
This is a per-client configuration: the resulting request factory is attached explicitly to the RestClient. Spring’s REST client reference and examples document this pattern. If the application uses other clients or creates request factories elsewhere, configure and review those paths separately.
#1 Best Overall
Configure a filter for auto-configured client builders
Spring also documents exposing a filter as a bean for auto-configured HTTP client builders. The following policy matches the IPv4 CIDR block and then excludes two addresses:
@Bean
InetAddressFilter httpClientInetAddressFilter() {
return InetAddressFilter.of("192.168.1.0/24")
.andNot("192.168.1.1", "192.168.1.10");
}
The example’s inclusion rule is limited to 192.168.1.0/24; andNot removes the listed addresses from that match. The bean approach is documented for auto-configured builders, not as a guarantee that manually constructed clients or every third-party client will inherit the policy. Check how each client in the application is created. See Spring’s configuration reference.
Choose a policy that matches the destinations you need
InetAddressFilter tests an InetAddress against address rules; it is not simply a check on the hostname text. Spring’s 4.1.1 API documentation describes IPv4 and IPv6 addresses and CIDR blocks, built-in address categories, and methods for composing rules.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →| Policy or method | What it is for | Practical consideration |
|---|---|---|
externalAddresses() |
Built-in filter for external addresses. | Useful when a client should not contact internal destinations; confirm that required destinations are permitted by the policy. |
internalAddresses() |
Built-in filter for internal addresses. | Use only when the intended policy is to match internal destinations. |
routable() |
Built-in filter for routable addresses. | Routability is an address classification, not a complete application-level trust decision. |
multicast() |
Built-in filter for multicast addresses. | Use when multicast matching is relevant to the client’s policy. |
specialPurpose() |
Built-in filter for special-purpose addresses. | Review the API’s defined behavior before relying on this category for a security boundary. |
of(...) |
Creates a filter from IPv4 or IPv6 addresses and CIDR blocks. | Can express a narrow allow policy, such as the CIDR rule in Spring’s bean example. |
and, or, andNot, negate |
Compose or invert filter logic. | Check the resulting match logic carefully; a mistaken combination can widen access rather than restrict it. |
These categories and composition methods are defined by Spring’s InetAddressFilter API. A broad external-address rule and an explicit CIDR rule solve different policy problems: the former is category-based, while the latter can constrain destinations to specified ranges. If internal services must be reachable, account for them deliberately rather than disabling destination checks wholesale.
What InetAddressFilter does not solve by itself
SSRF defenses need to account for the full request flow, not only a hostname or one address check. An attacker-controlled URL may resolve to an unsafe address, and DNS can change between validation and connection. The USENIX Security 2024 paper “Server-Side Request Forgery: Theory and Practice” discusses this DNS rebinding risk and describes IP pinning: resolve once, validate the result, and continue using that validated IP. A redirect can also send a request to a different destination, so reject redirects or validate each redirect target.
Those are general SSRF principles; the Spring reference does not establish identical DNS-resolution or redirect behavior for every underlying HTTP client and request flow. Confirm the behavior of the specific client you use before relying on the filter as protection against rebinding or redirect-based changes.
- Validate permitted URL schemes before making a request.
- Apply destination-address rules to each outbound client and code path that can reach user-controlled URLs.
- Decide explicitly whether redirects are rejected or whether every redirect destination is validated.
- Review any required internal-service access against the exposure created by permitting those destinations.
Keep product-specific SSRF settings separate
Spring Boot Admin documents its own SSRF protection, which is disabled by default in that product and can involve allowing selected internal CIDRs for service communication. That is Spring Boot Admin behavior, not a default setting for all Spring Boot HTTP clients. Consult the Spring Boot Admin 4.1.2 SSRF documentation if you are configuring that separate product.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallQuick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




