Spring WS Security
97%
Total Score
98
81
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-819079 spring-ws-security is vulnerable to Initialization of a Resource with an Insecure Default in versions 0.0.1 - 4.1.3 and 5.0.0 - 5.0.1. | 0.0.1 - 4.1.35.0.0 - 5.0.1 | High |
AIKIDO-2026-691427 spring-ws-security is vulnerable to Observable Discrepancy in versions 0.0.1 - 4.1.3 and 5.0.0 - 5.0.1. | 0.0.1 - 4.1.35.0.0 - 5.0.1 | Medium |
CVE-2026-40996 org.springframework.ws:spring-ws-security is vulnerable to Use of a Broken or Risky Cryptographic Algorithm in versions 5.0.0 - 5.0.1, 4.1.0 - 4.1.3, 4.0.0 - 4.0.18 and 3.1.0 - 3.1.8. | 3.1.0 - 3.1.84.0.0 - 4.0.184.1.0 - 4.1.3 +1 more | Medium |
CVE-2026-41000 org.springframework.ws:spring-ws-security is vulnerable to Authentication Bypass by Capture-replay in versions 5.0.0 - 5.0.1, 4.1.0 - 4.1.3, 4.0.0 - 4.0.18 and 3.1.0 - 3.1.8. | 3.1.0 - 3.1.84.0.0 - 4.0.184.1.0 - 4.1.3 +1 more | Low |
CVE-2026-40995 org.springframework.ws:spring-ws-security is vulnerable to Improper Authentication in versions 5.0.0 - 5.0.1, 4.1.0 - 4.1.3, 4.0.0 - 4.0.18 and 3.1.0 - 3.1.8. | 3.1.0 - 3.1.84.0.0 - 4.0.184.1.0 - 4.1.3 +1 more | Medium |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework.ws:spring-ws-core Version 5.0.2 | — | — |
org.springframework.ws:spring-xml Version 5.0.2 | — | — |
org.apache.santuario:xmlsec Version 4.0.4 | — | — |
org.apache.wss4j:wss4j-ws-security-dom Version 4.0.1 | — | — |
org.jvnet.staxex:stax-ex Version 2.1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.