CVE-2026-40975
MEDIUM
4,8
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: low
Integrity: low
Availability: none
Description
AI Translation Available
Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); random value property source / weak PRNG for secrets. Versions that are no longer supported are also affected per vendor advisory.
330
Use of Insufficiently Random Values
StableCommon Consequences
Security Scopes Affected:
Confidentiality
Other
Access Control
Potential Impacts:
Other
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Applicable Platforms
All platforms may be affected
Application
Spring Boot by Vmware
Version Range Affected
From
4.0.0
(inclusive)
To
4.0.6
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Spring Boot by Vmware
Version Range Affected
From
3.3.0
(inclusive)
To
3.3.19
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Spring Boot by Vmware
Version Range Affected
To
2.7.33
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Spring Boot by Vmware
Version Range Affected
From
3.4.0
(inclusive)
To
3.4.16
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Spring Boot by Vmware
Version Range Affected
From
3.5.0
(inclusive)
To
3.5.14
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://spring.io/security/cve-2026-40975