cbcvebase.
CVE-2026-40996
published 2026-06-11

CVE-2026-40996: Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound…

PriorityP425medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
0.13%
2.9th percentile
Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key material unless operators explicitly reconfigured the flag. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

Affected

4 ranges
VendorProductVersion rangeFixed in
springspring_web_services>= 3.1.0 < 3.1.93.1.9
springspring_web_services>= 4.0.0 < 4.0.194.0.19
springspring_web_services>= 4.1.0 < 4.1.3.14.1.3.1
springspring_web_services>= 5.0.0 < 5.0.1.15.0.1.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.