Improper validation of certificate with host mismatch in Spring Boot - CVE-2026-40974
Published: April 27, 2026
Spring Boot
Detailed vulnerability description
The vulnerability allows a remote attacker to compromise the confidentiality, integrity, and availability of data in transit.
The vulnerability exists due to improper certificate validation in Cassandra SSL auto-configuration when establishing an SSL connection to Cassandra. A remote attacker can intercept a connection on the local network to compromise the confidentiality, integrity, and availability of data in transit.