Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-40996 |
|
Fri, 12 Jun 2026 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring Web Services |
|
| Vendors & Products |
Spring
Spring spring Web Services |
Thu, 11 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key material unless operators explicitly reconfigured the flag. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8. | |
| Title | Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default | |
| Weaknesses | CWE-327 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-23T19:48:50.570Z
Reserved: 2026-04-16T02:19:12.969Z
Link: CVE-2026-40996
Updated: 2026-06-11T12:44:46.895Z
Status : Awaiting Analysis
Published: 2026-06-11T07:16:27.550
Modified: 2026-06-11T15:21:30.653
Link: CVE-2026-40996
No data.
OpenCVE Enrichment
Updated: 2026-06-11T10:40:19Z