Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-40972

Spring Boot DevTools: timing attack on the remote secret

Technology

Spring Boot

CVSS Score

7.5 / 10.0

Affected Versions

4.0.0 to 4.0.5; 3.5.0 to 3.5.13; 3.4.0 to 3.4.15; 3.3.0 to 3.3.18; 2.7.32 and earlier

Upstream Fix

4.0.6, 3.5.14 (public); 3.4.16, 3.3.19, 2.7.33 (Enterprise Support Only)

Published

April 28, 2026

OSSeva Coverage

Fixed upstream

Description

An attacker on the same network as an application running DevTools remote support may use a timing attack on the remote secret comparison to learn the secret. In extreme circumstances this lets the attacker upload changed classes and run code in the remote application. Fixed in 4.0.6 and 3.5.14, and in commercial 3.4.16, 3.3.19 and 2.7.33 releases. CVSS is VMware's score as the CNA.

Upstream record: NVD · CVE.org

Is your Spring Boot deployment affected?

If you're running 4.0.0 to 4.0.5; 3.5.0 to 3.5.13; 3.4.0 to 3.4.15; 3.3.0 to 3.3.18; 2.7.32 and earlier, you need this patch. Book a discovery call to get covered.