Server-Side Request Forgery (SSRF) in Spring Web Services - CVE-2026-40999

 

Server-Side Request Forgery (SSRF) in Spring Web Services - CVE-2026-40999

Published: August 28, 2026


Vulnerability identifier: #VU146190
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N]
CVE-ID: CVE-2026-40999
CWE-ID: CWE-918
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform server-side request forgery.

The vulnerability exists due to improper input validation in AbstractAddressingEndpointMapping handling of WS-Addressing reply destinations when processing non-anonymous ReplyTo or FaultTo addresses from request headers. A remote attacker can supply crafted WS-Addressing headers to perform server-side request forgery.

Only deployments with one or more configured WebServiceMessageSender instances for out-of-band replies that accept WS-Addressing headers from untrusted callers are vulnerable.


Affected software

Spring Web Services
IBM Sterling B2B Integrator
IBM Sterling File Gateway

How to mitigate CVE-2026-40999

Install security update from vendor's website.

Spring Web Services - addressed in versions 3.1.9, 4.0.19, 4.1.3.1, 4.1.4, 5.0.1.1, 5.0.2
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2.1, 6.2.2.1.1
IBM Sterling File Gateway - addressed in versions 6.2.1.2.1, 6.2.2.1.1

External References

Related Security Bulletins