CVE-2026-40994 Details
Description
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security on the network could therefore accept messages that violate BSP rules, weakening protocol-level checks. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
A vulnerability exists in the Wss4jSecurityInterceptor of Spring Web Services, where the default initialization of the WS-I Basic Security Profile (BSP) compliance flag disables crucial inbound validation. This flaw allows services that validate WS-Security over the network to accept messages that breach BSP regulations, particularly concerning signatures and related elements. As a result, the vulnerability undermines essential protocol-level safeguards designed to ensure the interoperable and secure application of WS-Security. The issue affects Spring Web Services versions 5.0.0 through 5.0.1, 4.1.0 through 4.1.3, 4.0.0 through 4.0.18, and 3.1.0 through 3.1.8, including versions no longer supported.
Users of affected versions should upgrade to the fixed version. For version 5.0.x, upgrade to 5.0.2 or 5.0.1.1 (Enterprise Support Only). For version 4.1.x, upgrade to 4.1.4 or 4.1.3.1 (Enterprise Support Only). For version 4.0.x, upgrade to 4.0.19 (Enterprise Support Only). For version 3.1.x, upgrade to 3.1.9 (Enterprise Support Only). If an upgrade is not possible, BSP compliance can be re-enabled by explicitly calling the setBspCompliant setter method with true as the argument.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://spring.io/security/cve-2026-40994 | [email protected] | Vendor AdvisoryMitigation |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1188 | Initialization of a Resource with an Insecure Default | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| broadcom spring web services | < 3.1.9 >= 4.0.0, < 4.0.19 >= 4.1.0, < 4.1.3.1 >= 5.0.0, < 5.0.1.1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 4, 2026 | Initial Analysis | [email protected] |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 23, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 11, 2026 | New CVE Received | [email protected] |