Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6mfm-98wv-32wm | Spring Web Services: X.509 authentication bypasses Spring Security account checks |
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-40995 |
|
Fri, 04 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Broadcom
Broadcom spring Web Services |
|
| CPEs | cpe:2.3:a:broadcom:spring_web_services:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Broadcom
Broadcom spring Web Services |
Tue, 23 Jun 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring Web Services |
|
| Vendors & Products |
Spring
Spring spring Web Services |
Thu, 11 Jun 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle checks (disabled, locked, expired, or credentials-expired accounts). Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8. | |
| Title | X.509 authentication bypasses Spring Security account checks | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-23T19:48:20.837Z
Reserved: 2026-04-16T02:19:12.969Z
Link: CVE-2026-40995
Updated: 2026-06-11T12:45:11.012Z
Status : Analyzed
Published: 2026-06-11T07:16:27.430
Modified: 2026-09-04T17:10:23.133
Link: CVE-2026-40995
No data.
OpenCVE Enrichment
Updated: 2026-06-11T10:40:21Z
Github GHSA