Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…
EPSS 0.3%top 76%

CVE-2026-40975: CWE-330: Use of Insufficiently Random Values in Spring Spring Boot

0
Medium
VulnerabilityCVE-2026-40975cvecve-2026-40975cwe-330
Published: 04/27/2026 (04/27/2026, 23:32:58 UTC)
Source: CVE Database V5
Vendor/Project: Spring
Product: Spring Boot

Description

Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); random value property source / weak PRNG for secrets. Versions that are no longer supported are also affected per vendor advisory.

CVSS v3.1

Score 4.8medium

Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Affected software

org.springframework.boot/spring-boot
pkg:maven/org.springframework.boot/spring-boot
Affected versions
=2.7.0=3.3.0=3.4.0=3.5.0=4.0.0

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 07/15/2026, 09:12:57 UTC

Technical Analysis

This vulnerability (CVE-2026-40975) in Spring Boot arises from the use of weak pseudo-random number generation for secrets via the ${random.value} property source. The values produced are insufficiently random and thus unsuitable for cryptographic secrets. While ${random.uuid} is not affected, numeric random values such as ${random.int} and ${random.long} should never be used for secrets due to their predictable numeric ranges. The issue affects multiple Spring Boot versions from 2.7.0 up to 4.0.5, with fixes released in subsequent patch versions. Red Hat advisories confirm the vulnerability and provide updates for affected products. The CVSS 3.1 base score is 4.8, indicating medium severity with low confidentiality and integrity impact and no availability impact. No known exploits in the wild have been reported. The vendor has released fixed versions addressing this weakness.

Potential Impact

The vulnerability allows the generation of secrets using insufficiently random values, which can lead to information disclosure or compromise of secret-based security mechanisms. The impact is limited to confidentiality and integrity with low severity, as indicated by the CVSS score of 4.8. There is no impact on availability. Exploitation could potentially allow attackers to predict or guess secrets generated by the affected random value property source, weakening security controls that rely on these secrets.

Mitigation Recommendations

Fixed versions of Spring Boot are available and should be applied: 2.7.33, 3.3.19, 3.4.16, 3.5.14, and 4.0.6 or later. Users should avoid using ${random.value}, ${random.int}, and ${random.long} for generating secrets and instead use ${random.uuid} or other cryptographically secure random generators. Refer to the Red Hat advisories for detailed patch information and update instructions. Patch status is confirmed by vendor advisories. No additional mitigation is required beyond applying the official fixes and avoiding insecure random value usage for secrets.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.2
Assigner Short Name
vmware
Date Reserved
2026-04-16T02:19:04.616Z
Cvss Version
3.1
State
PUBLISHED
Remediation Level
null
Vendor Advisory Urls
[{"url":"https://access.redhat.com/security/cve/CVE-2026-40975","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:25089","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:22619","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:21772","vendor":"Red Hat"},{"url":"https://access.redhat.com/errata/RHSA-2026:17668","vendor":"Red Hat"}]

Threat ID: 69f0134ecbff5d861057a5ce

Added to database: 04/28/2026, 01:54:22 UTC

Last enriched: 07/15/2026, 09:12:57 UTC

Last updated: 07/31/2026, 19:22:58 UTC

Views: 217

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses