cbcvebase.
CVE-2026-40999
published 2026-06-11

CVE-2026-40999: When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured…

PriorityP353high8.6CVSS 3.1
AVNACLPRNUINSCCHINAN
EPSS
0.38%
30.5th percentile
When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken directly from request headers without verifying that those destinations are safe to connect to. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

Affected

4 ranges
VendorProductVersion rangeFixed in
springspring_web_services>= 3.1.0 < 3.1.93.1.9
springspring_web_services>= 4.0.0 < 4.0.194.0.19
springspring_web_services>= 4.1.0 < 4.1.3.14.1.3.1
springspring_web_services>= 5.0.0 < 5.0.1.15.0.1.1
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.