CVE-2026-40996
published 2026-06-11CVE-2026-40996: Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound…
PriorityP425medium4.8CVSS 3.1
AVNACHPRNUINSUCLILAN
EPSS
0.13%
2.9th percentile
Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key material unless operators explicitly reconfigured the flag.
Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_web_services | >= 3.1.0 < 3.1.9 | 3.1.9 |
| spring | spring_web_services | >= 4.0.0 < 4.0.19 | 4.0.19 |
| spring | spring_web_services | >= 4.1.0 < 4.1.3.1 | 4.1.3.1 |
| spring | spring_web_services | >= 5.0.0 < 5.0.1.1 | 5.0.1.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Vmware Spring Web Services up to 3.1.8/4.0.18/4.1.3/5.0.1 risky encryption (CNNVD-202606-3062)
vuldb·2026-06-13·CVSS 4.8
CVE-2026-40996 [MEDIUM] Vmware Spring Web Services up to 3.1.8/4.0.18/4.1.3/5.0.1 risky encryption (CNNVD-202606-3062)
A vulnerability, which was classified as problematic, has been found in Vmware Spring Web Services up to 3.1.8/4.0.18/4.1.3/5.0.1. The affected element is an unknown function. The manipulation leads to risky cryptographic algorithm.
This vulnerability is listed as CVE-2026-40996. The attack may be initiated remotely. There is no available exploit.
It is advisable to upgrade the affected component.
GHSA
Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData.
ghsa_unreviewed·2026-06-11
CVE-2026-40996 [MEDIUM] CWE-327 Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData.
Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept RSA PKCS#1 v1.5 (rsa-1_5) encrypted key material unless operators explicitly reconfigured the flag.
Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-11
Published