Server-Side Request Forgery (SSRF) in Spring Web Services - CVE-2026-40999
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to perform server-side request forgery.
The vulnerability exists due to improper input validation in AbstractAddressingEndpointMapping handling of WS-Addressing reply destinations when processing non-anonymous ReplyTo or FaultTo addresses from request headers. A remote attacker can supply crafted WS-Addressing headers to perform server-side request forgery.
Only deployments with one or more configured WebServiceMessageSender instances for out-of-band replies that accept WS-Addressing headers from untrusted callers are vulnerable.
Affected software
IBM Sterling B2B Integrator
IBM Sterling File Gateway
How to mitigate CVE-2026-40999
IBM Sterling B2B Integrator - addressed in versions 6.2.1.2.1, 6.2.2.1.1
IBM Sterling File Gateway - addressed in versions 6.2.1.2.1, 6.2.2.1.1