Information Exposure Through Timing Discrepancy in spring-boot - CVE-2026-40972
Published: April 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to observable timing discrepancies in DevTools remote secret comparison when validating the remote secret over an adjacent network. A remote attacker can measure response timing to discover the secret and execute arbitrary code.
Exploitation is limited to attackers on the same network as the remote application, and successful secret recovery may allow uploading changed classes.
Affected software
Db2 Developer Extension
Library Support for Spring
How to mitigate CVE-2026-40972
Db2 Developer Extension - update to 1.1.2
Library Support for Spring - update to 3.4.18