CVE-2026-40975
Spring Boot: ${random.value} values are not suitable for use as secrets
Technology
Spring Boot
CVSS Score
7.5 / 10.0
Affected Versions
4.0.0 to 4.0.5; 3.5.0 to 3.5.13; 3.4.0 to 3.4.15; 3.3.0 to 3.3.18; 2.7.32 and earlier
Upstream Fix
4.0.6, 3.5.14 (public); 3.4.16, 3.3.19, 2.7.33 (Enterprise Support Only)
Published
April 28, 2026
OSSeva Coverage
Fixed upstream
Description
Values produced by the ${random.value} property source are not suitable for use as secrets. ${random.uuid} is not affected, and ${random.int} and ${random.long} should never be used for secrets because they are numeric values with a predictable range. NVD scores the record 7.5; VMware, as the CNA, scores it 4.8.
Is your Spring Boot deployment affected?
If you're running 4.0.0 to 4.0.5; 3.5.0 to 3.5.13; 3.4.0 to 3.4.15; 3.3.0 to 3.3.18; 2.7.32 and earlier, you need this patch. Book a discovery call to get covered.