WS-Security Compliance Issue in Spring Web Services by Pivotal Software
CVE-2026-40994
8.2HIGH
What is CVE-2026-40994?
A security misconfiguration in Spring Web Services allows the Wss4jSecurityInterceptor to operate with the Basic Security Profile (BSP) compliance flag incorrectly set. This misconfiguration results in the acceptance of WS-Security messages that do not comply with essential BSP rules, thus undermining the integrity of protocol-level validations. Services relying on these policies for secure message processing may inadvertently expose themselves to security risks.
Affected Version(s)
Spring Web Services 5.0.0 < 5.0.1.1
Spring Web Services 4.1.0 < 4.1.3.1
Spring Web Services 4.0.0 < 4.0.19
