CVE-2026-40970
published 2026-04-27CVE-2026-40970: When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the…
PriorityP432medium6.8CVSS 3.1
AVAACHPRNUINSUCHIHAN
EPSS
0.14%
3.4th percentile
When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server.
Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4j | — | — |
| devspaces | openvsx-rhel9 | — | — |
| devspaces | pluginregistry-rhel9 | — | — |
| log4j_2 | log4j | — | — |
| spring | spring_boot | >= 4.0.0 < 4.0.6 | 4.0.6 |
| vmware | spring_boot | >= 4.0.0 < 4.0.6 | 4.0.6 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Spring Boot's Elasticsearch auto-configuration doesn't perform hostname verification when connecting to the Elasticsearch server.
ghsa·2026-04-27
CVE-2026-40970 [MEDIUM] CWE-295 Spring Boot's Elasticsearch auto-configuration doesn't perform hostname verification when connecting to the Elasticsearch server.
Spring Boot's Elasticsearch auto-configuration doesn't perform hostname verification when connecting to the Elasticsearch server.
When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server.
Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.
VulDB
Vmware Spring Boot up to 4.0.5 Elasticsearch Auto-configuration certificate validation
vuldb·2026-04-27·CVSS 5.0
CVE-2026-40970 [MEDIUM] Vmware Spring Boot up to 4.0.5 Elasticsearch Auto-configuration certificate validation
A vulnerability, which was classified as critical, was found in Vmware Spring Boot up to 4.0.5. The impacted element is an unknown function of the component Elasticsearch Auto-configuration. Executing a manipulation can lead to improper certificate validation.
This vulnerability is tracked as CVE-2026-40970. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
Red Hat
Spring Boot: Spring Boot: Missing hostname verification in Elasticsearch auto-configuration allows information disclosure
vendor_redhat·2026-04-27·CVSS 5.0
CVE-2026-40970 [MEDIUM] CWE-295 Spring Boot: Spring Boot: Missing hostname verification in Elasticsearch auto-configuration allows information disclosure
Spring Boot: Spring Boot: Missing hostname verification in Elasticsearch auto-configuration allows information disclosure
A flaw was found in Spring Boot. When configured to use an SSL (Secure Sockets Layer) bundle, the Elasticsearch auto-configuration component does not perform hostname verification when establishing a connection to the Elasticsearch server. An attacker on an adjacent network could exploit this by performing a man-in-the-middle attack. This could lead to the disclosure or modification of sensitive information exchanged between Spring Boot and the Elasticsearch server.
Mitigation: To mitigate the risk of man-in-the-middle attacks, ensure that network communication between Spring Boot applications and Elasticsearch servers is protected. This can be achieved by deploying t
No detection rules found.
No public exploits indexed.
2026-04-27
Published