Intel

AIKIDO-2026-691427

spring-ws-security is vulnerable to Observable Discrepancy

Observable DiscrepancyCVE-2026-40997 Published Today

50

Medium Risk

This Affects:

javaspring-ws-security
0.0.1 - 3.1.8
Fixed in 3.1.9
4.0.0 - 4.0.18
Fixed in 4.0.19
4.1.0 - 4.1.3
Fixed in 4.1.3.1
5.0.0 - 5.0.1
Fixed in 5.0.1.1
Are you affected? Scan for Free

TL;DR

Spring Web Services Security may disclose account status information through SOAP authentication responses. In certain Spring Security integration paths, detailed authentication errors such as locked or disabled account states can be exposed to remote clients instead of generic authentication failures. An attacker can leverage these differences to enumerate valid user accounts and infer account status information, aiding further attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-ws-security is vulnerable to Observable Discrepancy in versions 0.0.1 - 3.1.8, 4.0.0 - 4.0.18, 4.1.0 - 4.1.3 and 5.0.0 - 5.0.1.

How to fix this

Upgrade the org.springframework.ws:spring-ws-security library to a patch version.