CVE-2026-40991

When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests are next executed. Affected versions: Spring REST Docs 4.0.0; 3.0.0 through 3.0.5; 2.0.0.RELEASE through 2.0.8.RELEASE.
References
Link Resource
https://spring.io/security/cve-2026-40991 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:broadcom:spring_rest_docs:*:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:spring_rest_docs:*:*:*:*:*:*:*:*
cpe:2.3:a:broadcom:spring_rest_docs:4.0.0:-:*:*:*:*:*:*

History

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) Al usar spring-restdocs-webtestclient o spring-restdocs-restassured para documentar una API remota accedida a través de HTTP, un atacante que compromete la API o engaña al usuario para que documente una API maliciosa puede realizar un ataque de inyección XXE cuando las pruebas de generación de documentación se ejecuten a continuación. Versiones afectadas: Spring REST Docs 4.0.0; 3.0.0 a 3.0.5; 2.0.0.RELEASE a 2.0.8.RELEASE.

17 Jul 2026, 20:29

Type Values Removed Values Added
First Time Broadcom
Broadcom spring Rest Docs
CPE cpe:2.3:a:broadcom:spring_rest_docs:4.0.0:-:*:*:*:*:*:*
cpe:2.3:a:broadcom:spring_rest_docs:*:*:*:*:*:*:*:*
References () https://spring.io/security/cve-2026-40991 - () https://spring.io/security/cve-2026-40991 - Vendor Advisory

10 Jun 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 00:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-40991

Mitre link : CVE-2026-40991

CVE.ORG link : CVE-2026-40991


JSON object : View

Products Affected

broadcom

  • spring_rest_docs
CWE
CWE-611

Improper Restriction of XML External Entity Reference