Back

HIGH

Spring Boot: Spring Boot: Weak pseudo-random number generation can lead to information disclosure.

Published Apr 27, 2026

Description

Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range.

Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); random value property source / weak PRNG for secrets. Versions that are no longer supported are also affected per vendor advisory.

Affected products

Remediation

Red Hat mitigation

Applications utilizing Spring Boot should avoid using the `${random.value}` property for generating cryptographic secrets or other security-sensitive data. Developers should review their application configurations and code to ensure that only cryptographically strong random number generators are used for such purposes. For UUID generation, `${random.uuid}` is not affected and can be used.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Apr 27, 2026
Updated Jul 15, 2026
Reserved Apr 16, 2026
CISA Vulnrichment
Updated Apr 28, 2026
NVD
Status Modified
Modified Jul 24, 2026
Red Hat
Severity Important
Public date Apr 27, 2026
ENISA EUVD
Assigner vmware
Published Apr 27, 2026
Updated Jul 15, 2026
Exploited since n/a
EUVD-2026-25939 GHSA-M4X9-HX6X-2C43