Information Exposure Through an Error Message in Spring gRPC - CVE-2026-40969
Published: April 28, 2026
Spring gRPC
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to information exposure through an error message in the gRPC status description when returning server-side AuthenticationException details to the client. A remote attacker can trigger an authentication failure to disclose sensitive information.