Security Flaw in Spring Web Services Allows Risky Key Transport Algorithm
CVE-2026-40996
4.8MEDIUM
What is CVE-2026-40996?
A configuration vulnerability in Spring Web Services allows the Wss4jSecurityInterceptor to accept the less secure RSA PKCS#1 v1.5 key transport algorithm by default. This can lead to security risks unless administrators reconfigure the allowances explicitly. This oversight compromises the integrity of inbound WS-Security decryption processes. To enhance security, it is imperative that operators adjust the defaults to prevent possible exploitation.
Affected Version(s)
Spring Web Services 5.0.0 < 5.0.1.1
Spring Web Services 4.1.0 < 4.1.3.1
Spring Web Services 4.0.0 < 4.0.19
