CVE-2026-40972
Spring Boot DevTools: timing attack on the remote secret
Technology
Spring Boot
CVSS Score
7.5 / 10.0
Affected Versions
4.0.0 to 4.0.5; 3.5.0 to 3.5.13; 3.4.0 to 3.4.15; 3.3.0 to 3.3.18; 2.7.32 and earlier
Upstream Fix
4.0.6, 3.5.14 (public); 3.4.16, 3.3.19, 2.7.33 (Enterprise Support Only)
Published
April 28, 2026
OSSeva Coverage
Fixed upstream
Description
An attacker on the same network as an application running DevTools remote support may use a timing attack on the remote secret comparison to learn the secret. In extreme circumstances this lets the attacker upload changed classes and run code in the remote application. Fixed in 4.0.6 and 3.5.14, and in commercial 3.4.16, 3.3.19 and 2.7.33 releases. CVSS is VMware's score as the CNA.
Is your Spring Boot deployment affected?
If you're running 4.0.0 to 4.0.5; 3.5.0 to 3.5.13; 3.4.0 to 3.4.15; 3.3.0 to 3.3.18; 2.7.32 and earlier, you need this patch. Book a discovery call to get covered.