DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk4 min

Spring Boot SSRF Mitigation with InetAddressFilter: Setup and Limits

Spring Boot 4.1’s InetAddressFilter restricts HTTP client destinations by IP address. Learn per-client and bean configuration, address policies, and the SSRF risks it does not handle alone.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Spring Boot 4.1.0 introduced InetAddressFilter, which lets HTTP clients restrict outgoing requests by destination IP address. For a single client, attach a filter through HttpClientSettings; for auto-configured client builders, define an InetAddressFilter bean. This is a useful SSRF control, but it does not replace URL validation, redirect checks, or review of every outbound client path.

Which Spring Boot versions support InetAddressFilter?

Spring announced the feature with Spring Boot 4.1.0 on June 10, 2026. The configuration examples are in the Spring Boot 4.1 reference, and the API documentation cited here is for Spring Boot 4.1.1. Do not assume the feature is available in earlier Spring Boot versions based on these references. Spring’s 4.1.0 release announcement identifies the release, while the Spring Boot 4.1 REST client reference describes its configuration for blocking and reactive clients.

As an Amazon Associate I earn from qualifying purchases.

Configure a filter for one RestClient

To apply the broad built-in external-address policy to a particular JDK-backed RestClient, pass the filter to HttpClientSettings when building the request factory:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
InetAddressFilter onlyExternalAddresses = InetAddressFilter.externalAddresses();

HttpClientSettings settings = HttpClientSettings.defaults()
    .withInetAddressFilter(onlyExternalAddresses);

ClientHttpRequestFactory requestFactory = ClientHttpRequestFactoryBuilder.jdk()
    .build(settings);

RestClient restClient = RestClient.builder()
    .requestFactory(requestFactory)
    .baseUrl("https://example.org")
    .build();

This is a per-client configuration: the resulting request factory is attached explicitly to the RestClient. Spring’s REST client reference and examples document this pattern. If the application uses other clients or creates request factories elsewhere, configure and review those paths separately.

#1 Best Overall

Configure a filter for auto-configured client builders

Spring also documents exposing a filter as a bean for auto-configured HTTP client builders. The following policy matches the IPv4 CIDR block and then excludes two addresses:

@Bean
InetAddressFilter httpClientInetAddressFilter() {
    return InetAddressFilter.of("192.168.1.0/24")
        .andNot("192.168.1.1", "192.168.1.10");
}

The example’s inclusion rule is limited to 192.168.1.0/24; andNot removes the listed addresses from that match. The bean approach is documented for auto-configured builders, not as a guarantee that manually constructed clients or every third-party client will inherit the policy. Check how each client in the application is created. See Spring’s configuration reference.

Choose a policy that matches the destinations you need

InetAddressFilter tests an InetAddress against address rules; it is not simply a check on the hostname text. Spring’s 4.1.1 API documentation describes IPv4 and IPv6 addresses and CIDR blocks, built-in address categories, and methods for composing rules.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Policy or method What it is for Practical consideration
externalAddresses() Built-in filter for external addresses. Useful when a client should not contact internal destinations; confirm that required destinations are permitted by the policy.
internalAddresses() Built-in filter for internal addresses. Use only when the intended policy is to match internal destinations.
routable() Built-in filter for routable addresses. Routability is an address classification, not a complete application-level trust decision.
multicast() Built-in filter for multicast addresses. Use when multicast matching is relevant to the client’s policy.
specialPurpose() Built-in filter for special-purpose addresses. Review the API’s defined behavior before relying on this category for a security boundary.
of(...) Creates a filter from IPv4 or IPv6 addresses and CIDR blocks. Can express a narrow allow policy, such as the CIDR rule in Spring’s bean example.
and, or, andNot, negate Compose or invert filter logic. Check the resulting match logic carefully; a mistaken combination can widen access rather than restrict it.

These categories and composition methods are defined by Spring’s InetAddressFilter API. A broad external-address rule and an explicit CIDR rule solve different policy problems: the former is category-based, while the latter can constrain destinations to specified ranges. If internal services must be reachable, account for them deliberately rather than disabling destination checks wholesale.

What InetAddressFilter does not solve by itself

SSRF defenses need to account for the full request flow, not only a hostname or one address check. An attacker-controlled URL may resolve to an unsafe address, and DNS can change between validation and connection. The USENIX Security 2024 paper “Server-Side Request Forgery: Theory and Practice” discusses this DNS rebinding risk and describes IP pinning: resolve once, validate the result, and continue using that validated IP. A redirect can also send a request to a different destination, so reject redirects or validate each redirect target.

Those are general SSRF principles; the Spring reference does not establish identical DNS-resolution or redirect behavior for every underlying HTTP client and request flow. Confirm the behavior of the specific client you use before relying on the filter as protection against rebinding or redirect-based changes.

  • Validate permitted URL schemes before making a request.
  • Apply destination-address rules to each outbound client and code path that can reach user-controlled URLs.
  • Decide explicitly whether redirects are rejected or whether every redirect destination is validated.
  • Review any required internal-service access against the exposure created by permitting those destinations.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Keep product-specific SSRF settings separate

Spring Boot Admin documents its own SSRF protection, which is disabled by default in that product and can involve allowing selected internal CIDRs for service communication. That is Spring Boot Admin behavior, not a default setting for all Spring Boot HTTP clients. Consult the Spring Boot Admin 4.1.2 SSRF documentation if you are configuring that separate product.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.