Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-40975

Spring Boot: ${random.value} values are not suitable for use as secrets

Technology

Spring Boot

CVSS Score

7.5 / 10.0

Affected Versions

4.0.0 to 4.0.5; 3.5.0 to 3.5.13; 3.4.0 to 3.4.15; 3.3.0 to 3.3.18; 2.7.32 and earlier

Upstream Fix

4.0.6, 3.5.14 (public); 3.4.16, 3.3.19, 2.7.33 (Enterprise Support Only)

Published

April 28, 2026

OSSeva Coverage

Fixed upstream

Description

Values produced by the ${random.value} property source are not suitable for use as secrets. ${random.uuid} is not affected, and ${random.int} and ${random.long} should never be used for secrets because they are numeric values with a predictable range. NVD scores the record 7.5; VMware, as the CNA, scores it 4.8.

Upstream record: NVD · CVE.org

Is your Spring Boot deployment affected?

If you're running 4.0.0 to 4.0.5; 3.5.0 to 3.5.13; 3.4.0 to 3.4.15; 3.3.0 to 3.3.18; 2.7.32 and earlier, you need this patch. Book a discovery call to get covered.