MEDIUM
Spring gRPC AuthenticationException message reflected to remote client
Published Apr 28, 2026
5.3
MEDIUMCVSS 3.1
EPSS 0.33%
Description
The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks.
Affected versions: Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.
Affected products
-
- Version 1.0.0StatusaffectedConstraints<1.0.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Spring | Spring gRPC | unaffected |
|
- < 1.0.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26064 Advisory
- https://github.com/advisories/GHSA-37w2-q6vh-45v6 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40969
- https://spring.io/security/cve-2026-40969 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-26064 | Advisory | |
| https://github.com/advisories/GHSA-37w2-q6vh-45v6 | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-40969 | ||
| https://spring.io/security/cve-2026-40969 | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Apr 28, 2026
Updated Apr 28, 2026
Reserved Apr 16, 2026
Link CVE-2026-40969
CISA Vulnrichment
Updated Apr 28, 2026
ENISA EUVD
EUVD-2026-26064 GHSA-37W2-Q6VH-45V6 Assigner vmware
Published Apr 28, 2026
Updated Apr 28, 2026
Exploited since n/a
Link EUVD-2026-26064