Intel

AIKIDO-2026-10586

spring-boot-elasticsearch is vulnerable to Improper Certificate Validation

Improper Certificate ValidationCVE-2026-40970 Published Apr 27, 2026

50

Medium Risk

This Affects:

JAVAspring-boot-elasticsearch
4.0.0 - 4.0.5
Fixed in 4.0.6
Are you affected? Scan for Free

TL;DR

Affected versions of this package are vulnerable to improper validation of certificate hostnames in Elasticsearch auto-configuration when using an SSL bundle, causing TLS connections to trust certificates without verifying they match the intended server hostname. This can enable machine-in-the-middle attacks against Elasticsearch traffic.

Who does this affect?

You are affected if using a vulnerable version and you are connecting to Elasticsearch.

Background info

spring-boot-elasticsearch is vulnerable to Improper Certificate Validation in versions 4.0.0 - 4.0.5.

How to fix this

Upgrade the org.springframework.boot:spring-boot-elasticsearch library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform