Spring Boot: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison
Published Apr 27, 2026
7.5
HIGHCVSS 3.1
EPSS 0.33%
Description
An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.
Affected products
-
Affected
- ≥ 2.7.0, < 2.7.33
- ≥ 3.3.0, < 3.3.19
- ≥ 3.4.0, < 3.4.16
- ≥ 3.5.0, < 3.5.14
- ≥ 4.0.0, < 4.0.6
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Spring | Spring Boot | unaffected | Affected
|
- < 2.7.33
- ≥ 3.3.0 · < 3.3.19
- ≥ 3.4.0 · < 3.4.16
- ≥ 3.5.0 · < 3.5.14
- ≥ 4.0.0 · < 4.0.6
No data.
HawtIO HawtIO 4.4.0
spring-boot
Fixed · RHSA-2026:25089
Red Hat OpenShift Dev Spaces 3.28
devspaces/openvsx-rhel9:1779528224
Fixed · RHSA-2026:21772
Red Hat OpenShift Dev Spaces 3.28
devspaces/pluginregistry-rhel9:1779359423
Fixed · RHSA-2026:21772
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14
spring-boot
Fixed · RHSA-2026:17668
Red Hat AMQ Broker 7
spring-boot
Not affected
Red Hat AMQ Clients
spring-boot
Not affected
Red Hat Data Grid 8
spring-boot
Not affected
Red Hat Enterprise Linux 8
log4j:2/log4j
Not affected
Red Hat Enterprise Linux 9
log4j
Not affected
Red Hat Fuse 7
spring-boot
Will not fix
Red Hat JBoss Enterprise Application Platform 7
spring-boot
Not affected
Red Hat JBoss Enterprise Application Platform 8
spring-boot
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
spring-boot
Not affected
Red Hat Process Automation 7
spring-boot
Not affected
Red Hat Single Sign-On 7
spring-boot
Not affected
Red Hat build of OptaPlanner 8
spring-boot
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| HawtIO HawtIO 4.4.0 | spring-boot | Fixed | RHSA-2026:25089 |
| Red Hat OpenShift Dev Spaces 3.28 | devspaces/openvsx-rhel9:1779528224 | Fixed | RHSA-2026:21772 |
| Red Hat OpenShift Dev Spaces 3.28 | devspaces/pluginregistry-rhel9:1779359423 | Fixed | RHSA-2026:21772 |
| Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 | spring-boot | Fixed | RHSA-2026:17668 |
| Red Hat AMQ Broker 7 | spring-boot | Not affected | n/a |
| Red Hat AMQ Clients | spring-boot | Not affected | n/a |
| Red Hat Data Grid 8 | spring-boot | Not affected | n/a |
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Not affected | n/a |
| Red Hat Enterprise Linux 9 | log4j | Not affected | n/a |
| Red Hat Fuse 7 | spring-boot | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | spring-boot | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | spring-boot | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-boot | Not affected | n/a |
| Red Hat Process Automation 7 | spring-boot | Not affected | n/a |
| Red Hat Single Sign-On 7 | spring-boot | Not affected | n/a |
| Red Hat build of OptaPlanner 8 | spring-boot | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
To mitigate this issue, disable the Spring Boot DevTools remote functionality in production environments. This feature is primarily intended for development and should not be enabled in publicly accessible deployments. To disable remote DevTools, ensure the `spring.devtools.remote.secret` property is not configured, or explicitly set `spring.devtools.remote.enabled=false` in your application's `application.properties` or `application.yml` file. Example for `application.properties`: `spring.devtools.remote.enabled=false` Disabling this feature may impact development workflows that rely on remote DevTools capabilities. A restart of the application is required for the changes to take effect.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-40972 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2463332 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25936 Advisory
- https://github.com/advisories/GHSA-56v8-86gj-66jp Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40972
- https://spring.io/security/cve-2026-40972 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-40972
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub