CVE-2026-40970Disclosure(vmware / spring_boot)

LOWCVSS 6.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch vmware spring_boot systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_boot

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-04-27); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
spring_boot

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-27: 1Mentions · 2026-04-28: 1Mentions · 2026-05-17: 1Patch / Workaround · 2026-04-27: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-28: 1Technical Details · 2026-05-17: 104-2704-2805-17
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-271
Disclosure1
2026-04-281
General1
2026-05-171
Disclosure1
Full discourse3 posts
  • Israel@f1tym1
    Disclosure

    CVE-2026-40970 | Vmware Spring Boot up to 4.0.5 Elasticsearch Auto-configuration certificate validation https://ift.tt/LomOD7w A vulnerability, which was classified as critical, was found in Vmware Spring Boot up to 4.0.5. The impacted element is an unknown function of the com…

    Post summary

    The post announces a critical CVE (CVE-2026-40970) affecting VMware Spring Boot up to 4.0.5, specifically the Elasticsearch auto‑configuration certificate validation component, but provides no evidence of exploitation or remediation.

    0000044
    974 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-40970 Missing Hostname Verification in Spring Boot Elasticsearch SSL Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-40970

    Post summary

    The post cites CVE-2026-40970 as a missing hostname verification flaw in Spring Boot Elasticsearch SSL configuration, but offers no additional details such as PoC, exploit code, or patch information.

    0000048
    4.0K followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: Spring Boot SSL bundle bug in CVE-2026-40970 and CVE-2026-40971 disables TLS hostname verification for Elasticsearch and RabbitMQ, exposing apps to MITM until upgraded. https://threatcluster.io/cluster/critical-vulnerabilities-in-spring-boots-ssl-configuration-f-b593581f

    Post summary

    Spring Boot SSL bundle bug CVE‑2026‑40970 and CVE‑2026‑40971 disable TLS hostname verification for Elasticsearch and RabbitMQ, exposing applications to MITM attacks until an upgrade or patch is applied.

    0000066
    160 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_boot---

Explore more