CVE-2026-40975

Published: Apr 28, 2026 Last Modified: Apr 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:
MEDIUM 4,8
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: none

Description

AI Translation Available

Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range.

Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); random value property source / weak PRNG for secrets. Versions that are no longer supported are also affected per vendor advisory.

330

Use of Insufficiently Random Values

Stable
Common Consequences
Security Scopes Affected:
Confidentiality Other Access Control
Potential Impacts:
Other Bypass Protection Mechanism Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
View CWE Details
Application

Spring Boot by Vmware

Version Range Affected
From 4.0.0 (inclusive)
To 4.0.6 (exclusive)
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Spring Boot by Vmware

Version Range Affected
From 3.3.0 (inclusive)
To 3.3.19 (exclusive)
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Spring Boot by Vmware

Version Range Affected
To 2.7.33 (exclusive)
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Spring Boot by Vmware

Version Range Affected
From 3.4.0 (inclusive)
To 3.4.16 (exclusive)
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Spring Boot by Vmware

Version Range Affected
From 3.5.0 (inclusive)
To 3.5.14 (exclusive)
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://spring.io/security/cve-2026-40975