Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. com.github.ulisesbocchio/jasypt-spring-boot
  4. ›
  5. CVE-2026-9370

CVE-2026-9370: jasypt-spring-boot Uses a One-Way Hash without a Salt

May 26, 2026 (updated June 30, 2026)

A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeySaltGenerator of the file jasypt-spring-boot/src/main/java/com/ulisesbocchio/jasyptspringboot/encryptor/SimpleGCMConfig.java of the component Password Hash Handler. Executing a manipulation can lead to use of a one-way hash with a predictable salt. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

References

  • github.com/advisories/GHSA-jgj7-c8vj-w563
  • github.com/dntyfate/cve/issues/3
  • github.com/ulisesbocchio/jasypt-spring-boot
  • github.com/ulisesbocchio/jasypt-spring-boot/issues/431
  • nvd.nist.gov/vuln/detail/CVE-2026-9370
  • vuldb.com/submit/813198
  • vuldb.com/vuln/365333
  • vuldb.com/vuln/365333/cti

Code Behaviors & Features

Detect and mitigate CVE-2026-9370 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.0.0 up to 4.0.4

Solution

Unfortunately, there is no solution available yet.

Impact 3.7 LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Learn more about CVSS

Weakness

  • CWE-759: Use of a One-Way Hash without a Salt

Source file

maven/com.github.ulisesbocchio/jasypt-spring-boot/CVE-2026-9370.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 11 Jul 2026 00:17:57 +0000.