CVE-2026-40975: CWE-330: Use of Insufficiently Random Values in Spring Spring Boot
Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); random value property source / weak PRNG for secrets. Versions that are no longer supported are also affected per vendor advisory.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-40975) in Spring Boot arises from the use of weak pseudo-random number generation for secrets via the ${random.value} property source. The values produced are insufficiently random and thus unsuitable for cryptographic secrets. While ${random.uuid} is not affected, numeric random values such as ${random.int} and ${random.long} should never be used for secrets due to their predictable numeric ranges. The issue affects multiple Spring Boot versions from 2.7.0 up to 4.0.5, with fixes released in subsequent patch versions. Red Hat advisories confirm the vulnerability and provide updates for affected products. The CVSS 3.1 base score is 4.8, indicating medium severity with low confidentiality and integrity impact and no availability impact. No known exploits in the wild have been reported. The vendor has released fixed versions addressing this weakness.
Potential Impact
The vulnerability allows the generation of secrets using insufficiently random values, which can lead to information disclosure or compromise of secret-based security mechanisms. The impact is limited to confidentiality and integrity with low severity, as indicated by the CVSS score of 4.8. There is no impact on availability. Exploitation could potentially allow attackers to predict or guess secrets generated by the affected random value property source, weakening security controls that rely on these secrets.
Mitigation Recommendations
Fixed versions of Spring Boot are available and should be applied: 2.7.33, 3.3.19, 3.4.16, 3.5.14, and 4.0.6 or later. Users should avoid using ${random.value}, ${random.int}, and ${random.long} for generating secrets and instead use ${random.uuid} or other cryptographically secure random generators. Refer to the Red Hat advisories for detailed patch information and update instructions. Patch status is confirmed by vendor advisories. No additional mitigation is required beyond applying the official fixes and avoiding insecure random value usage for secrets.
CVE-2026-40975: CWE-330: Use of Insufficiently Random Values in Spring Spring Boot
Description
Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); random value property source / weak PRNG for secrets. Versions that are no longer supported are also affected per vendor advisory.
CVSS v3.1
Score 4.8medium
Affected software
pkg:maven/org.springframework.boot/spring-bootRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-40975) in Spring Boot arises from the use of weak pseudo-random number generation for secrets via the ${random.value} property source. The values produced are insufficiently random and thus unsuitable for cryptographic secrets. While ${random.uuid} is not affected, numeric random values such as ${random.int} and ${random.long} should never be used for secrets due to their predictable numeric ranges. The issue affects multiple Spring Boot versions from 2.7.0 up to 4.0.5, with fixes released in subsequent patch versions. Red Hat advisories confirm the vulnerability and provide updates for affected products. The CVSS 3.1 base score is 4.8, indicating medium severity with low confidentiality and integrity impact and no availability impact. No known exploits in the wild have been reported. The vendor has released fixed versions addressing this weakness.
Potential Impact
The vulnerability allows the generation of secrets using insufficiently random values, which can lead to information disclosure or compromise of secret-based security mechanisms. The impact is limited to confidentiality and integrity with low severity, as indicated by the CVSS score of 4.8. There is no impact on availability. Exploitation could potentially allow attackers to predict or guess secrets generated by the affected random value property source, weakening security controls that rely on these secrets.
Mitigation Recommendations
Fixed versions of Spring Boot are available and should be applied: 2.7.33, 3.3.19, 3.4.16, 3.5.14, and 4.0.6 or later. Users should avoid using ${random.value}, ${random.int}, and ${random.long} for generating secrets and instead use ${random.uuid} or other cryptographically secure random generators. Refer to the Red Hat advisories for detailed patch information and update instructions. Patch status is confirmed by vendor advisories. No additional mitigation is required beyond applying the official fixes and avoiding insecure random value usage for secrets.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- vmware
- Date Reserved
- 2026-04-16T02:19:04.616Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-40975","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25089","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22619","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21772","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17668","vendor":"Red Hat"}]
Threat ID: 69f0134ecbff5d861057a5ce
Added to database: 04/28/2026, 01:54:22 UTC
Last enriched: 07/15/2026, 09:12:57 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 217
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.