CVE-2026-41001
- EPSS 0.09%
- Veröffentlicht 11.06.2026 05:04:28
- Zuletzt bearbeitet 04.09.2026 18:13:58
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same host can pre-create this predictable directory or p...
- EPSS 0.12%
- Veröffentlicht 11.06.2026 05:03:53
- Zuletzt bearbeitet 04.09.2026 18:05:38
Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected. Affected versions: Spring Boo...
CVE-2026-40977
- EPSS 0.11%
- Veröffentlicht 27.04.2026 23:36:06
- Zuletzt bearbeitet 24.07.2026 21:10:00
When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), ...
CVE-2026-40976
- EPSS 0.49%
- Veröffentlicht 27.04.2026 23:34:51
- Zuletzt bearbeitet 24.07.2026 21:10:00
In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its ...
CVE-2026-40975
- EPSS 0.31%
- Veröffentlicht 27.04.2026 23:32:58
- Zuletzt bearbeitet 24.07.2026 21:10:00
Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range. Affected: Spring Boot 4.0....
CVE-2026-40974
- EPSS 0.18%
- Veröffentlicht 27.04.2026 23:31:40
- Zuletzt bearbeitet 24.07.2026 21:10:00
Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fi...
- EPSS 0.14%
- Veröffentlicht 27.04.2026 23:29:51
- Zuletzt bearbeitet 24.07.2026 21:10:00
A local attacker on the same host as the application may be able to take control of the directory used by `ApplicationTemp`. When `server.servlet.session.persistent` is set to `true` and the attack persists across application restarts, this may allow...
CVE-2026-40972
- EPSS 0.26%
- Veröffentlicht 27.04.2026 23:15:19
- Zuletzt bearbeitet 24.07.2026 21:10:00
An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed ...
CVE-2026-40971
- EPSS 0.16%
- Veröffentlicht 27.04.2026 22:45:13
- Zuletzt bearbeitet 24.07.2026 21:10:00
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor adviso...
CVE-2026-40970
- EPSS 0.14%
- Veröffentlicht 27.04.2026 19:16:52
- Zuletzt bearbeitet 14.05.2026 16:09:59
When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory...