When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to connect to.
Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-40999 |
Configurations
No configuration.
History
11 Jun 2026, 07:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-11 07:16
Updated : 2026-06-17 10:46
NVD link : CVE-2026-40999
Mitre link : CVE-2026-40999
CVE.ORG link : CVE-2026-40999
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
