The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks.
Affected versions:
Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-40969 | Vendor Advisory |
Configurations
History
30 Apr 2026, 13:24
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:vmware:spring_grpc:*:*:*:*:*:*:*:* | |
| First Time |
Vmware spring Grpc
Vmware |
|
| References | () https://spring.io/security/cve-2026-40969 - Vendor Advisory |
28 Apr 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-28 15:16
Updated : 2026-04-30 13:24
NVD link : CVE-2026-40969
Mitre link : CVE-2026-40969
CVE.ORG link : CVE-2026-40969
JSON object : View
Products Affected
vmware
- spring_grpc
CWE
CWE-209
Generation of Error Message Containing Sensitive Information
