CVE-2026-40974
Spring Boot: Cassandra auto-configuration does not verify the server hostname over SSL
Technology
Spring Boot
CVSS Score
9.8 / 10.0
Affected Versions
4.0.0 to 4.0.5; 3.5.0 to 3.5.13; 3.4.0 to 3.4.15; 3.3.0 to 3.3.18; 2.7.32 and earlier
Upstream Fix
4.0.6, 3.5.14 (public); 3.4.16, 3.3.19, 2.7.33 (Enterprise Support Only)
Published
April 28, 2026
OSSeva Coverage
Fixed upstream
Description
Spring Boot's Cassandra auto-configuration does not perform hostname verification when it establishes an SSL connection to Cassandra, so an attacker who can intercept the connection can present a certificate for another host. NVD scores the record 9.8; VMware, as the CNA, scores it 5.0 with an adjacent-network, high-complexity vector. Fixed in 4.0.6 and 3.5.14, and in commercial 3.4.16, 3.3.19 and 2.7.33 releases.
Is your Spring Boot deployment affected?
If you're running 4.0.0 to 4.0.5; 3.5.0 to 3.5.13; 3.4.0 to 3.4.15; 3.3.0 to 3.3.18; 2.7.32 and earlier, you need this patch. Book a discovery call to get covered.