← Retour à la recherche de CVE

CVE-2026-40998

Spring Web Services

Description

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK-s default DocumentBuilderFactory behavior instead of Spring-s hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could therefore be exposed to XML External Entity (XXE) style attacks. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

CVSS 8.2EPSS 0.35200000000000004%Risque 0.85
Voir la source
Publication
2026-06-11 07:16:27
Versions concernées
>=5.0.0,<5.0.2, >=4.1.0,<4.1.4, >=4.0.0,<4.0.19, >=3.1.0,<3.1.9
Type
Bibliothèque
Vecteur
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N