Spring / Spring Web Services
8 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41000 | WSS4J validation does not use configured replay cache | LOW | 3.7 | Jun 11, 2026 |
| CVE-2026-40999 | Spring WS SSRF via unvalidated WS-Addressing reply destinations | HIGH | 8.6 | Jun 11, 2026 |
| CVE-2026-40998 | Jaxp13 XPath XXE via StreamSource and SAXSource | HIGH | 8.2 | Jun 11, 2026 |
| CVE-2026-40997 | SOAP security faults leak Spring Security account state | MEDIUM | 5.3 | Jun 11, 2026 |
| CVE-2026-40996 | Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default | MEDIUM | 4.8 | Jun 11, 2026 |
| CVE-2026-40995 | X.509 authentication bypasses Spring Security account checks | MEDIUM | 5.4 | Jun 11, 2026 |
| CVE-2026-40994 | Wss4jSecurityInterceptor disables WS-I BSP validation by default | HIGH | 8.2 | Jun 11, 2026 |
| CVE-2019-3773 | Spring Web Services XML External Entity Injection (XXE) | CRITICAL | 9.8 | Jan 18, 2019 |
Showing 1 to 8 of 8 CVEs