Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8v8j-3hxp-93wr | Spring Boot's default security filter chain has no authorization rule with Actuator but without Health |
Thu, 14 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Default Web Security Misconfiguration in Spring Boot | Spring Boot: Spring Boot: Security bypass due to ineffective default web security |
| Weaknesses | CWE-305 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 30 Apr 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Vmware
Vmware spring Boot |
|
| CPEs | cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Vmware
Vmware spring Boot |
Tue, 28 Apr 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 28 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Default Web Security Misconfiguration in Spring Boot |
Tue, 28 Apr 2026 04:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring Boot |
|
| Vendors & Products |
Spring
Spring spring Boot |
Mon, 27 Apr 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In certain circumstances, Spring Boot's default web security is ineffective allowing unauthorized access to all endpoints. For an application to be vulnerable, it must: be a servlet-based web application; have no Spring Security configuration of its own and rely on the default web security filter chain; depend on spring-boot-actuator-autoconfigure; not depend on spring-boot-health. If any of the above does not apply, the application is not vulnerable. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory. | |
| Weaknesses | CWE-862 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-04-29T03:55:41.205Z
Reserved: 2026-04-16T02:19:04.616Z
Link: CVE-2026-40976
Updated: 2026-04-28T13:54:57.821Z
Status : Analyzed
Published: 2026-04-28T00:16:24.803
Modified: 2026-04-30T13:54:12.847
Link: CVE-2026-40976
OpenCVE Enrichment
Updated: 2026-05-14T14:30:16Z
Github GHSA