Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.springframework.boot/spring-boot-devtools
  4. ›
  5. CVE-2026-40972

CVE-2026-40972: Spring Boot DevTools remote secret comparison is vulnerable to timing attacks

April 28, 2026 (updated May 6, 2026)

An attacker on the same network as the remote application may be able to utilize a timing attack to discover information about the remote secret. In extreme circumstances this could result in the attacker determining the secret and uploading changed classes, thereby achieving remote code execution in the remote application.

Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); DevTools remote secret comparison. Versions that are no longer supported are also affected per vendor advisory.

References

  • github.com/advisories/GHSA-56v8-86gj-66jp
  • github.com/spring-projects/spring-boot
  • nvd.nist.gov/vuln/detail/CVE-2026-40972
  • spring.io/security/cve-2026-40972

Code Behaviors & Features

Detect and mitigate CVE-2026-40972 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 2.7.32, all versions starting from 3.3.0 up to 3.3.18, all versions starting from 3.4.0 up to 3.4.15, all versions starting from 3.5.0 before 3.5.14, all versions starting from 4.0.0 before 4.0.6

Fixed versions

  • 4.0.6
  • 3.5.14

Solution

Upgrade to versions 3.5.14, 4.0.6 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-208: Observable Timing Discrepancy

Source file

maven/org.springframework.boot/spring-boot-devtools/CVE-2026-40972.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 09 May 2026 12:19:34 +0000.