CVE-2026-40969

The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks. Affected versions: Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.
References
Link Resource
https://spring.io/security/cve-2026-40969 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:vmware:spring_grpc:*:*:*:*:*:*:*:*

History

30 Apr 2026, 13:24

Type Values Removed Values Added
CPE cpe:2.3:a:vmware:spring_grpc:*:*:*:*:*:*:*:*
First Time Vmware spring Grpc
Vmware
References () https://spring.io/security/cve-2026-40969 - () https://spring.io/security/cve-2026-40969 - Vendor Advisory

28 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 15:16

Updated : 2026-04-30 13:24


NVD link : CVE-2026-40969

Mitre link : CVE-2026-40969

CVE.ORG link : CVE-2026-40969


JSON object : View

Products Affected

vmware

  • spring_grpc
CWE
CWE-209

Generation of Error Message Containing Sensitive Information