Replay Cache Vulnerability in Spring Web Services Affecting Multiple Versions
CVE-2026-41000

3.7LOW

Key Information:

Vendor

Spring

Vendor
CVE Published:
11 June 2026

What is CVE-2026-41000?

The vulnerability arises from the Wss4jSecurityInterceptor's inconsistent integration of Apache WSS4J ReplayCache instances into RequestData for validation-time checks. This oversight can lead to insufficient protection against the replay of UsernameToken nonces, creation timestamps, Timestamp elements, and certain one-time-use semantics associated with SAML. Consequently, even when configured appropriately, the replay cache on the interceptor may be ineffective, raising substantial security concerns for applications relying on these mechanisms to safeguard sensitive data.

Affected Version(s)

Spring Web Services 5.0.0 < 5.0.1.1

Spring Web Services 4.1.0 < 4.1.3.1

Spring Web Services 4.0.0 < 4.0.19

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.