Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.springframework.ws/spring-xml
  4. ›
  5. CVE-2026-40998

CVE-2026-40998: Spring Web Services: Jaxp13 XPath XXE via StreamSource and SAXSource

June 11, 2026 (updated August 21, 2026)

Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK’s default DocumentBuilderFactory behavior instead of Spring’s hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could therefore be exposed to XML External Entity (XXE) style attacks.

Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.

References

  • github.com/advisories/GHSA-2mpf-m756-hxjm
  • github.com/spring-projects/spring-ws/commit/eb8d66c0995d1e1dd5bfcfb657c8c9de21266d97
  • nvd.nist.gov/vuln/detail/CVE-2026-40998
  • spring.io/security/cve-2026-40998

Code Behaviors & Features

Detect and mitigate CVE-2026-40998 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 3.1.0 up to 3.1.8, all versions starting from 4.0.0 up to 4.0.18, all versions starting from 4.1.0 before 4.1.4, all versions starting from 5.0.0 before 5.0.2

Fixed versions

  • 4.1.4
  • 5.0.2

Solution

Upgrade to versions 4.1.4, 5.0.2 or above.

Impact 8.2 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-611: Improper Restriction of XML External Entity Reference

Source file

maven/org.springframework.ws/spring-xml/CVE-2026-40998.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 22 Aug 2026 00:17:54 +0000.