Remote Code Execution Risk in Spring Web Services by Pivotal
CVE-2026-40999
8.6HIGH
What is CVE-2026-40999?
This vulnerability allows Spring Web Services to initiate unsafe outbound connections to unverified destinations when WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses. By taking destination information directly from request headers without adequate validation, attackers could potentially exploit this flaw to send malicious requests or gain unauthorized access to sensitive data. Users are encouraged to review the patched versions to mitigate this risk.
Affected Version(s)
Spring Web Services 5.0.0 < 5.0.1.1
Spring Web Services 4.1.0 < 4.1.3.1
Spring Web Services 4.0.0 < 4.0.19
