Spring Web Services
Broadcom · 8 CVEs
CVE-2026-41000
LOW
WSS4J validation does not use configured replay cache
Jun 11, 2026
CVE-2026-40999
HIGH
Spring WS SSRF via unvalidated WS-Addressing reply destinations
Jun 11, 2026
CVE-2026-40998
HIGH
Jaxp13 XPath XXE via StreamSource and SAXSource
Jun 11, 2026
CVE-2026-40997
MEDIUM
SOAP security faults leak Spring Security account state
Jun 11, 2026
CVE-2026-40996
MEDIUM
Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default
Jun 11, 2026
CVE-2026-40995
MEDIUM
X.509 authentication bypasses Spring Security account checks
Jun 11, 2026
CVE-2026-40994
HIGH
Wss4jSecurityInterceptor disables WS-I BSP validation by default
Jun 11, 2026
CVE-2019-3773
CRITICAL
Spring Web Services XML External Entity Injection (XXE)
Jan 18, 2019
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-41000 | WSS4J validation does not use configured replay cache | LOW | 0.26% | Jun 11, 2026 |
| CVE-2026-40999 | Spring WS SSRF via unvalidated WS-Addressing reply destinations | HIGH | 0.43% | Jun 11, 2026 |
| CVE-2026-40998 | Jaxp13 XPath XXE via StreamSource and SAXSource | HIGH | 0.39% | Jun 11, 2026 |
| CVE-2026-40997 | SOAP security faults leak Spring Security account state | MEDIUM | 0.46% | Jun 11, 2026 |
| CVE-2026-40996 | Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default | MEDIUM | 0.15% | Jun 11, 2026 |
| CVE-2026-40995 | X.509 authentication bypasses Spring Security account checks | MEDIUM | 0.18% | Jun 11, 2026 |
| CVE-2026-40994 | Wss4jSecurityInterceptor disables WS-I BSP validation by default | HIGH | 0.34% | Jun 11, 2026 |
| CVE-2019-3773 | Spring Web Services XML External Entity Injection (XXE) | CRITICAL | 4.11% | Jan 18, 2019 |
Showing 1 to 8 of 8 CVEs