Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); Cassandra SSL auto-configuration. Versions that are no longer supported are also affected per vendor advisory.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mqvw-jfmh-93qq | Spring Boot's Cassandra SSL auto-configuration disables TLS hostname verification |
Thu, 14 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware spring Boot |
|
| CPEs | cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vmware
Vmware spring Boot |
Mon, 04 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cassandra SSL Hostname Verification Bypass in Spring Boot Auto‑Configuration | Spring Boot: Cassandra: Spring Boot: Security bypass in Cassandra SSL connections |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 28 Apr 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cassandra SSL Hostname Verification Bypass in Spring Boot Auto‑Configuration |
Tue, 28 Apr 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 02:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring Boot |
|
| Vendors & Products |
Spring
Spring spring Boot |
Mon, 27 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); Cassandra SSL auto-configuration. Versions that are no longer supported are also affected per vendor advisory. | |
| Weaknesses | CWE-295 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-04-28T12:41:52.250Z
Reserved: 2026-04-16T02:19:04.615Z
Link: CVE-2026-40974
Updated: 2026-04-28T12:41:48.185Z
Status : Analyzed
Published: 2026-04-28T00:16:24.523
Modified: 2026-05-14T16:00:26.880
Link: CVE-2026-40974
OpenCVE Enrichment
Updated: 2026-04-28T19:45:07Z
Github GHSA