CVE-2026-40971: Critical severity VMware Spring Boot vulnerability
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Spring Bootto a version that resolves this vulnerability.Fixed in 4.0.6 - Upgrade
Upgrade
Spring Bootto a version that resolves this vulnerability.Fixed in 3.5.14
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40971?
CVE-2026-40971 is classified as a medium severity vulnerability.
How do I fix CVE-2026-40971?
To fix CVE-2026-40971, upgrade to Spring Boot version 4.0.6 or 3.5.14 or later.
Which versions of Spring Boot are affected by CVE-2026-40971?
CVE-2026-40971 affects Spring Boot versions 4.0.0 to 4.0.5 and 3.5.0 to 3.5.13.
What issue does CVE-2026-40971 cause in Spring Boot?
CVE-2026-40971 causes Spring Boot's RabbitMQ auto-configuration to skip hostname verification when using an SSL bundle.
Is there a workaround for CVE-2026-40971 while waiting for an update?
Currently, it is recommended to upgrade to the patched versions as there are no official workarounds for CVE-2026-40971.