Use of a broken or risky cryptographic algorithm in Spring Web Services - CVE-2026-40996

 

Use of a broken or risky cryptographic algorithm in Spring Web Services - CVE-2026-40996

Published: August 28, 2026


Vulnerability identifier: #VU146187
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-40996
CWE-ID: CWE-327
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information or modify data.

The vulnerability exists due to the use of a legacy cryptographic algorithm in Wss4jSecurityInterceptor when processing inbound WS-Security decryption with RSA PKCS#1 v1.5 key transport. A remote attacker can leverage acceptance of rsa-1_5 encrypted key material to disclose sensitive information or modify data.

Exploitation requires inbound XML encryption or key transport handled through WSS4J and peers that negotiate or emit RSA v1.5 key transport, and is relevant in man-in-the-middle or oracle-capable positions.


Affected software

Spring Web Services

How to mitigate CVE-2026-40996

Install security update from vendor's website.

Spring Web Services - addressed in versions 3.1.9, 4.0.19, 4.1.3.1, 4.1.4, 5.0.1.1, 5.0.2

External References

Related Security Bulletins