CVE-2026-40972

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.
References
Link Resource
https://spring.io/security/cve-2026-40972 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*

History

30 Apr 2026, 14:26

Type Values Removed Values Added
References () https://spring.io/security/cve-2026-40972 - () https://spring.io/security/cve-2026-40972 - Vendor Advisory
CPE cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
First Time Vmware
Vmware spring Boot

28 Apr 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-28 00:16

Updated : 2026-04-30 14:26


NVD link : CVE-2026-40972

Mitre link : CVE-2026-40972

CVE.ORG link : CVE-2026-40972


JSON object : View

Products Affected

vmware

  • spring_boot
CWE
CWE-208

Observable Timing Discrepancy