Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-40974

Spring Boot: Cassandra auto-configuration does not verify the server hostname over SSL

Technology

Spring Boot

CVSS Score

9.8 / 10.0

Affected Versions

4.0.0 to 4.0.5; 3.5.0 to 3.5.13; 3.4.0 to 3.4.15; 3.3.0 to 3.3.18; 2.7.32 and earlier

Upstream Fix

4.0.6, 3.5.14 (public); 3.4.16, 3.3.19, 2.7.33 (Enterprise Support Only)

Published

April 28, 2026

OSSeva Coverage

Fixed upstream

Description

Spring Boot's Cassandra auto-configuration does not perform hostname verification when it establishes an SSL connection to Cassandra, so an attacker who can intercept the connection can present a certificate for another host. NVD scores the record 9.8; VMware, as the CNA, scores it 5.0 with an adjacent-network, high-complexity vector. Fixed in 4.0.6 and 3.5.14, and in commercial 3.4.16, 3.3.19 and 2.7.33 releases.

Upstream record: NVD · CVE.org

Is your Spring Boot deployment affected?

If you're running 4.0.0 to 4.0.5; 3.5.0 to 3.5.13; 3.4.0 to 3.4.15; 3.3.0 to 3.3.18; 2.7.32 and earlier, you need this patch. Book a discovery call to get covered.