Back

HIGH

Spring Boot: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison

Published Apr 27, 2026

Description

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application.

Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.

Affected products

Remediation

Red Hat mitigation

To mitigate this issue, disable the Spring Boot DevTools remote functionality in production environments. This feature is primarily intended for development and should not be enabled in publicly accessible deployments. To disable remote DevTools, ensure the `spring.devtools.remote.secret` property is not configured, or explicitly set `spring.devtools.remote.enabled=false` in your application's `application.properties` or `application.yml` file. Example for `application.properties`: `spring.devtools.remote.enabled=false` Disabling this feature may impact development workflows that rely on remote DevTools capabilities. A restart of the application is required for the changes to take effect.

Weaknesses (1)

References (7)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner vmware
Published Apr 27, 2026
Updated Apr 29, 2026
Reserved Apr 16, 2026

CISA Vulnrichment

Updated Apr 28, 2026

NVD

Status Analyzed
Modified Jul 24, 2026

Red Hat

Severity Moderate
Public date Apr 27, 2026
Bugzilla 2463332

ENISA EUVD

Assigner vmware
Published Apr 27, 2026
Updated Apr 29, 2026