Spring Boot: Spring Boot: Weak pseudo-random number generation can lead to information disclosure.
Published Apr 27, 2026
8.2
HIGHCVSS 3.1
EPSS 0.41%
Description
Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); random value property source / weak PRNG for secrets. Versions that are no longer supported are also affected per vendor advisory.
Affected products
-
- Version 2.7.0StatusaffectedConstraints<2.7.33
- Version 3.3.0StatusaffectedConstraints<3.3.19
- Version 3.4.0StatusaffectedConstraints<3.4.16
- Version 3.5.0StatusaffectedConstraints<3.5.14
- Version 4.0.0StatusaffectedConstraints<4.0.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Spring | Spring Boot | unaffected |
|
- < 2.7.33
- ≥ 3.3.0 · < 3.3.19
- ≥ 3.4.0 · < 3.4.16
- ≥ 3.5.0 · < 3.5.14
- ≥ 4.0.0 · < 4.0.6
No data.
AMQ Clients 2026.Q3
spring-boot
Fixed · RHSA-2026:69459
HawtIO HawtIO 4.4.0
spring-boot
Fixed · RHSA-2026:25089
Red Hat Data Grid 8.6.1
spring-boot
Fixed · RHSA-2026:22619
Red Hat OpenShift Dev Spaces 3.28
devspaces/openvsx-rhel9:1779528224
Fixed · RHSA-2026:21772
Red Hat OpenShift Dev Spaces 3.28
devspaces/pluginregistry-rhel9:1779359423
Fixed · RHSA-2026:21772
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14
spring-boot
Fixed · RHSA-2026:17668
Red Hat AMQ Broker 7
spring-boot
Not affected
Red Hat Enterprise Linux 8
log4j:2/log4j
Not affected
Red Hat Enterprise Linux 9
log4j
Not affected
Red Hat Fuse 7
spring-boot
Will not fix
Red Hat JBoss Enterprise Application Platform 7
spring-boot
Not affected
Red Hat JBoss Enterprise Application Platform 8
spring-boot
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
spring-boot
Not affected
Red Hat Process Automation 7
spring-boot
Not affected
Red Hat Single Sign-On 7
spring-boot
Not affected
Red Hat build of OptaPlanner 8
spring-boot
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| AMQ Clients 2026.Q3 | spring-boot | Fixed | RHSA-2026:69459 |
| HawtIO HawtIO 4.4.0 | spring-boot | Fixed | RHSA-2026:25089 |
| Red Hat Data Grid 8.6.1 | spring-boot | Fixed | RHSA-2026:22619 |
| Red Hat OpenShift Dev Spaces 3.28 | devspaces/openvsx-rhel9:1779528224 | Fixed | RHSA-2026:21772 |
| Red Hat OpenShift Dev Spaces 3.28 | devspaces/pluginregistry-rhel9:1779359423 | Fixed | RHSA-2026:21772 |
| Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 | spring-boot | Fixed | RHSA-2026:17668 |
| Red Hat AMQ Broker 7 | spring-boot | Not affected | n/a |
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Not affected | n/a |
| Red Hat Enterprise Linux 9 | log4j | Not affected | n/a |
| Red Hat Fuse 7 | spring-boot | Will not fix | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | spring-boot | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | spring-boot | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-boot | Not affected | n/a |
| Red Hat Process Automation 7 | spring-boot | Not affected | n/a |
| Red Hat Single Sign-On 7 | spring-boot | Not affected | n/a |
| Red Hat build of OptaPlanner 8 | spring-boot | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Applications utilizing Spring Boot should avoid using the `${random.value}` property for generating cryptographic secrets or other security-sensitive data. Developers should review their application configurations and code to ensure that only cryptographically strong random number generators are used for such purposes. For UUID generation, `${random.uuid}` is not affected and can be used.
References (12)
- https://access.redhat.com/errata/RHSA-2026:17668
- https://access.redhat.com/errata/RHSA-2026:21772
- https://access.redhat.com/errata/RHSA-2026:22619
- https://access.redhat.com/errata/RHSA-2026:25089
- https://access.redhat.com/security/cve/CVE-2026-40975 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2463331 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25939 Advisory
- https://github.com/advisories/GHSA-m4x9-hx6x-2c43 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40975
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40975.json
- https://spring.io/security/cve-2026-40975 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-40975
Change history (0)
No recorded changes yet.