CVE-2026-40972
published 2026-04-28CVE-2026-40972: An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme…
PriorityP347high7.5CVSS 3.1
AVAACHPRNUINSUCHIHAH
EPSS
0.26%
17.7th percentile
An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| devspaces | openvsx-rhel9 | — | — |
| devspaces | pluginregistry-rhel9 | — | — |
| spring | spring_boot | >= 2.7.0 < 2.7.33 | 2.7.33 |
| spring | spring_boot | >= 3.3.0 < 3.3.19 | 3.3.19 |
| spring | spring_boot | >= 3.4.0 < 3.4.16 | 3.4.16 |
| spring | spring_boot | >= 3.5.0 < 3.5.14 | 3.5.14 |
| spring | spring_boot | >= 4.0.0 < 4.0.6 | 4.0.6 |
| vmware | spring_boot | < 2.7.33 | 2.7.33 |
| vmware | spring_boot | >= 3.3.0 < 3.3.19 | 3.3.19 |
| vmware | spring_boot | >= 3.4.0 < 3.4.16 | 3.4.16 |
| vmware | spring_boot | >= 3.5.0 < 3.5.14 | 3.5.14 |
| vmware | spring_boot | >= 4.0.0 < 4.0.6 | 4.0.6 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Spring Boot: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison
vendor_redhat·2026-04-27·CVSS 7.5
CVE-2026-40972 [HIGH] CWE-208 Spring Boot: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison
Spring Boot: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison
A flaw was found in Spring Boot. An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about a remote secret. In extreme circumstances, this could allow the attacker to determine the secret and upload changed classes, leading to remote code execution in the remote application.
Mitigation: To mitigate this issue, disable the Spring Boot DevTools remote functionality in production environments. This feature is primarily intended for development and should not be enabled in publicly accessible deployments.
To disable remote DevTools, ensure the `spring.devtools.remote.secret` property is not configured, or explicitly set `s
VulDB
Vmware Spring Boot up to 4.0.5 DevTools timing discrepancy
vuldb·2026-04-28·CVSS 7.5
CVE-2026-40972 [HIGH] Vmware Spring Boot up to 4.0.5 DevTools timing discrepancy
A vulnerability was found in Vmware Spring Boot up to 2.7.32/3.3.18/3.4.15/3.5.13/4.0.5 and classified as problematic. Affected by this issue is some unknown functionality of the component DevTools. Such manipulation leads to observable timing discrepancy.
This vulnerability is listed as CVE-2026-40972. The attack must be carried out from within the local network. There is no available exploit.
It is suggested to upgrade the affected component.
GHSA
Spring Boot DevTools remote secret comparison is vulnerable to timing attacks
ghsa·2026-04-28
CVE-2026-40972 [HIGH] CWE-208 Spring Boot DevTools remote secret comparison is vulnerable to timing attacks
Spring Boot DevTools remote secret comparison is vulnerable to timing attacks
An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-40972 maven-shade-plugin: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison [fedora-all]
bugzilla·2026-05-08·CVSS 7.5
CVE-2026-40972 [HIGH] CVE-2026-40972 maven-shade-plugin: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison [fedora-all]
CVE-2026-40972 maven-shade-plugin: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40972 log4j: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison [fedora-all]
bugzilla·2026-05-08·CVSS 7.5
CVE-2026-40972 [HIGH] CVE-2026-40972 log4j: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison [fedora-all]
CVE-2026-40972 log4j: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40972 Spring Boot: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison
bugzilla·2026-04-28·CVSS 7.5
CVE-2026-40972 [HIGH] CVE-2026-40972 Spring Boot: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison
CVE-2026-40972 Spring Boot: Spring Boot: Remote code execution via timing attack in DevTools remote secret comparison
An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.
2026-04-28
Published