PT-2026-48621 · Vmware · Spring Web Services
CVE-2026-40998
·
Published
2026-06-11
·
Updated
2026-06-23
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Spring Web Services versions 5.0.0 through 5.0.1
Spring Web Services versions 4.1.0 through 4.1.3
Spring Web Services versions 4.0.0 through 4.0.18
Spring Web Services versions 3.1.0 through 3.1.8
Description
Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. This allows applications evaluating XPath against untrusted XML payloads to be exposed to XML External Entity (XXE) attacks, where an external entity is referenced within an XML document to potentially disclose internal files or perform server-side requests.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spring Web Services