PT-2026-48621 · Vmware · Spring Web Services

CVE-2026-40998

·

Published

2026-06-11

·

Updated

2026-06-23

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions Spring Web Services versions 5.0.0 through 5.0.1 Spring Web Services versions 4.1.0 through 4.1.3 Spring Web Services versions 4.0.0 through 4.0.18 Spring Web Services versions 3.1.0 through 3.1.8
Description Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. This allows applications evaluating XPath against untrusted XML payloads to be exposed to XML External Entity (XXE) attacks, where an external entity is referenced within an XML document to potentially disclose internal files or perform server-side requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40998
GHSA-2MPF-M756-HXJM

Affected Products

Spring Web Services