Intel

AIKIDO-2026-845610

spring-restdocs-restassured is vulnerable to XML External Entity (XXE) Injection

XML External Entity (XXE) InjectionCVE-2026-40991 Published Jun 12, 2026

60

Medium Risk

This Affects:

JAVAspring-restdocs-restassured
0.0.1 - 3.0.5
Fixed in 3.0.6
4.0.0 - 4.0.0
Fixed in 4.0.1
Are you affected? Scan for Free

TL;DR

When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests are next executed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-restdocs-restassured is vulnerable to XML External Entity (XXE) Injection in versions 0.0.1 - 3.0.5 and 4.0.0 - 4.0.0.

How to fix this

Upgrade the org.springframework.restdocs:spring-restdocs-restassured library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform