← Browse

CVE-2026-40999

Medium

Elevated severity or exploit probability.

CVSS base
8.6 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
EPSS — probability of exploitation (30 days)
0.4%
32.2th percentile
CISA KEV
Not listed
Weakness / dates
CWE-918
Published 2026-06-11 · modified 2026-09-04

CVSS breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Attack VectorNNetwork
Attack ComplexityLLow
Privileges RequiredNNone
User InteractionNNone
ScopeCChanged
ConfidentialityHHigh
IntegrityNNone
AvailabilityNNone

Timeline

Description

When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to connect to. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

Affected

broadcom

References

Official: NVD · CVE.org