An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-40972 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
30 Apr 2026, 14:26
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://spring.io/security/cve-2026-40972 - Vendor Advisory | |
| CPE | cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:* | |
| First Time |
Vmware
Vmware spring Boot |
28 Apr 2026, 00:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-28 00:16
Updated : 2026-04-30 14:26
NVD link : CVE-2026-40972
Mitre link : CVE-2026-40972
CVE.ORG link : CVE-2026-40972
JSON object : View
Products Affected
vmware
- spring_boot
CWE
CWE-208
Observable Timing Discrepancy
