Intel

AIKIDO-2026-10583

spring-boot is vulnerable to Insecure Randomness

Insecure RandomnessCVE-2026-40975 Published Apr 27, 2026

60

Medium Risk

This Affects:

JAVAspring-boot
2.7.0 - 3.5.13
Fixed in 3.5.14
4.0.0 - 4.0.5
Fixed in 4.0.6
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to the use of a weak pseudo-random number generator in the random value property source, causing ${random.value} to generate values unsuitable for use as secrets. Predictable or low-entropy values may weaken tokens, passwords, or other security-sensitive data derived from these properties.

Who does this affect?

You are affected if using a vulnerable version.

Background info

spring-boot is vulnerable to Insecure Randomness in versions 2.7.0 - 3.5.13 and 4.0.0 - 4.0.5.

How to fix this

Upgrade the org.springframework.boot:spring-boot library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform