CVE-2026-40977
published 2026-04-28CVE-2026-40977: When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the…
PriorityP433medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.11%
1.6th percentile
When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); PID file / symlink behavior (`ApplicationPidFileWriter`). Versions that are no longer supported are also affected per vendor advisory.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | log4j | — | — |
| devspaces | openvsx-rhel9 | — | — |
| devspaces | pluginregistry-rhel9 | — | — |
| log4j_2 | log4j | — | — |
| spring | spring_boot | >= 2.7.0 < 2.7.33 | 2.7.33 |
| spring | spring_boot | >= 3.3.0 < 3.3.19 | 3.3.19 |
| spring | spring_boot | >= 3.4.0 < 3.4.16 | 3.4.16 |
| spring | spring_boot | >= 3.5.0 < 3.5.14 | 3.5.14 |
| spring | spring_boot | >= 4.0.0 < 4.0.6 | 4.0.6 |
| vmware | spring_boot | < 2.7.33 | 2.7.33 |
| vmware | spring_boot | >= 3.3.0 < 3.3.19 | 3.3.19 |
| vmware | spring_boot | >= 3.4.0 < 3.4.16 | 3.4.16 |
| vmware | spring_boot | >= 3.5.0 < 3.5.14 | 3.5.14 |
| vmware | spring_boot | >= 4.0.0 < 4.0.6 | 4.0.6 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Spring Boot: Spring Boot: Local file corruption via PID file manipulation
vendor_redhat·2026-04-27·CVSS 4.7
CVE-2026-40977 [MEDIUM] CWE-59 Spring Boot: Spring Boot: Local file corruption via PID file manipulation
Spring Boot: Spring Boot: Local file corruption via PID file manipulation
A flaw was found in Spring Boot when an application is configured to use `ApplicationPidFileWriter`. A local attacker with write access to the PID file's location can exploit this vulnerability to corrupt one arbitrary file on the host each time the application is started. This can lead to data integrity issues or a denial of service (DoS) by rendering critical system files unusable.
Package: spring-boot (Red Hat AMQ Broker 7) - Fix deferred
Package: spring-boot (Red Hat AMQ Clients) - Fix deferred
Package: spring-boot (Red Hat build of Apache Camel for Spring Boot 4) - Fix deferred
Package: spring-boot (Red Hat build of Apache Camel - HawtIO 4) - Fix deferred
Package: spring-boot (Red Hat build of OptaPlanner
GHSA
Spring Boot's PID file write follows symlinks at predictable default path
ghsa·2026-04-28
CVE-2026-40977 [MEDIUM] CWE-59 Spring Boot's PID file write follows symlinks at predictable default path
Spring Boot's PID file write follows symlinks at predictable default path
When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); PID file / symlink behavior (`ApplicationPidFileWriter`). Versions that are no longer supported are also affected per vendor advisory.
VulDB
Vmware Spring Boot up to 4.0.5 PID File ApplicationPidFileWriter link following
vuldb·2026-04-28·CVSS 4.7
CVE-2026-40977 [MEDIUM] Vmware Spring Boot up to 4.0.5 PID File ApplicationPidFileWriter link following
A vulnerability was found in Vmware Spring Boot up to 2.7.32/3.3.18/3.4.15/3.5.13/4.0.5. It has been declared as critical. The affected element is the function ApplicationPidFileWriter of the component PID File Handler. The manipulation results in link following.
This vulnerability is cataloged as CVE-2026-40977. The attack must be initiated from a local position. There is no exploit available.
It is recommended to upgrade the affected component.
No detection rules found.
No public exploits indexed.
2026-04-28
Published