Spring Boot: Spring Boot: Local file corruption via PID file manipulation
Published Apr 27, 2026
6.7
MEDIUMCVSS 3.1
EPSS 0.15%
Description
When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); PID file / symlink behavior (`ApplicationPidFileWriter`). Versions that are no longer supported are also affected per vendor advisory.
Affected products
-
- Version 2.7.0StatusaffectedConstraints<2.7.33
- Version 3.3.0StatusaffectedConstraints<3.3.19
- Version 3.4.0StatusaffectedConstraints<3.4.16
- Version 3.5.0StatusaffectedConstraints<3.5.14
- Version 4.0.0StatusaffectedConstraints<4.0.6
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Spring | Spring Boot | unaffected |
|
- < 2.7.33
- ≥ 3.3.0 · < 3.3.19
- ≥ 3.4.0 · < 3.4.16
- ≥ 3.5.0 · < 3.5.14
- ≥ 4.0.0 · < 4.0.6
No data.
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14
n/a
Fixed · RHSA-2026:17668
Red Hat AMQ Broker 7
spring-boot
Fix deferred
Red Hat AMQ Clients
spring-boot
Fix deferred
Red Hat Data Grid 8
spring-boot
Fix deferred
Red Hat Enterprise Linux 8
log4j:2/log4j
Fix deferred
Red Hat Enterprise Linux 9
log4j
Out of support scope
Red Hat Fuse 7
spring-boot
Fix deferred
Red Hat JBoss Enterprise Application Platform 7
spring-boot
Fix deferred
Red Hat JBoss Enterprise Application Platform 8
spring-boot
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
spring-boot
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/openvsx-rhel9
Fix deferred
Red Hat OpenShift Dev Spaces
devspaces/pluginregistry-rhel9
Fix deferred
Red Hat Process Automation 7
spring-boot
Fix deferred
Red Hat Single Sign-On 7
spring-boot
Fix deferred
Red Hat build of Apache Camel - HawtIO 4
spring-boot
Fix deferred
Red Hat build of Apache Camel for Spring Boot 4
spring-boot
Fix deferred
Red Hat build of OptaPlanner 8
spring-boot
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 | n/a | Fixed | RHSA-2026:17668 |
| Red Hat AMQ Broker 7 | spring-boot | Fix deferred | n/a |
| Red Hat AMQ Clients | spring-boot | Fix deferred | n/a |
| Red Hat Data Grid 8 | spring-boot | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | log4j | Out of support scope | n/a |
| Red Hat Fuse 7 | spring-boot | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | spring-boot | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | spring-boot | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-boot | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/openvsx-rhel9 | Fix deferred | n/a |
| Red Hat OpenShift Dev Spaces | devspaces/pluginregistry-rhel9 | Fix deferred | n/a |
| Red Hat Process Automation 7 | spring-boot | Fix deferred | n/a |
| Red Hat Single Sign-On 7 | spring-boot | Fix deferred | n/a |
| Red Hat build of Apache Camel - HawtIO 4 | spring-boot | Fix deferred | n/a |
| Red Hat build of Apache Camel for Spring Boot 4 | spring-boot | Fix deferred | n/a |
| Red Hat build of OptaPlanner 8 | spring-boot | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-40977 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2463329 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25941 Advisory
- https://github.com/advisories/GHSA-5368-6h4h-gr29 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40977
- https://spring.io/security/cve-2026-40977 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-40977
Change history (0)
No recorded changes yet.