CVE-2026-40994
published 2026-06-11CVE-2026-40994: Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on…
PriorityP348high8.2CVSS 3.1
AVNACLPRNUINSUCLIHAN
EPSS
0.23%
13.7th percentile
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks.
Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_web_services | >= 3.1.0 < 3.1.9 | 3.1.9 |
| spring | spring_web_services | >= 4.0.0 < 4.0.19 | 4.0.19 |
| spring | spring_web_services | >= 4.1.0 < 4.1.3.1 | 4.1.3.1 |
| spring | spring_web_services | >= 5.0.0 < 5.0.1.1 | 5.0.1.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Vmware Spring Web Services up to 3.1.8/4.0.18/4.1.3/5.0.1 insecure default initialization of resource (CNNVD-202606-3064)
vuldb·2026-06-13·CVSS 8.2
CVE-2026-40994 [HIGH] Vmware Spring Web Services up to 3.1.8/4.0.18/4.1.3/5.0.1 insecure default initialization of resource (CNNVD-202606-3064)
A vulnerability has been found in Vmware Spring Web Services up to 3.1.8/4.0.18/4.1.3/5.0.1 and classified as critical. This affects an unknown function. This manipulation causes insecure default initialization of resource.
This vulnerability is registered as CVE-2026-40994. Remote exploitation of the attack is possible. No exploit is available.
The affected component should be upgraded.
GHSA
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData.
ghsa_unreviewed·2026-06-11
CVE-2026-40994 [HIGH] CWE-1188 Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData.
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks.
Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-11
Published