Package Health

org.springframework.ws:spring-ws-security

Spring WS Security

Latest 5.0.2MavenMaven

97%

Total Score

Maintainer Stability
Maintainer Stability
Assesses the consistency and reliability of package maintainers

98

Dependencies
Dependencies
Evaluates the health and security of package dependencies

81

Maturity
Maturity
Indicates package age, release frequency, and adoption metrics

100

Supply Chain
Supply Chain
Evaluates supply chain security practices and risks

100

Are you affected? Scan for Free

Vulnerabilities

TitleVersionsSeverity
AIKIDO-2026-819079
spring-ws-security is vulnerable to Initialization of a Resource with an Insecure Default in versions 0.0.1 - 4.1.3 and 5.0.0 - 5.0.1.
0.0.1 - 4.1.35.0.0 - 5.0.1
High
AIKIDO-2026-691427
spring-ws-security is vulnerable to Observable Discrepancy in versions 0.0.1 - 4.1.3 and 5.0.0 - 5.0.1.
0.0.1 - 4.1.35.0.0 - 5.0.1
Medium
CVE-2026-40996
org.springframework.ws:spring-ws-security is vulnerable to Use of a Broken or Risky Cryptographic Algorithm in versions 5.0.0 - 5.0.1, 4.1.0 - 4.1.3, 4.0.0 - 4.0.18 and 3.1.0 - 3.1.8.
3.1.0 - 3.1.84.0.0 - 4.0.184.1.0 - 4.1.3 +1 more
Medium
CVE-2026-41000
org.springframework.ws:spring-ws-security is vulnerable to Authentication Bypass by Capture-replay in versions 5.0.0 - 5.0.1, 4.1.0 - 4.1.3, 4.0.0 - 4.0.18 and 3.1.0 - 3.1.8.
3.1.0 - 3.1.84.0.0 - 4.0.184.1.0 - 4.1.3 +1 more
Low
CVE-2026-40995
org.springframework.ws:spring-ws-security is vulnerable to Improper Authentication in versions 5.0.0 - 5.0.1, 4.1.0 - 4.1.3, 4.0.0 - 4.0.18 and 3.1.0 - 3.1.8.
3.1.0 - 3.1.84.0.0 - 4.0.184.1.0 - 4.1.3 +1 more
Medium

Package versions

Maintainers

No maintainer information available.

Direct Dependencies

DependencyLast ReleaseScore
org.springframework.ws:spring-ws-core
Version 5.0.2
org.springframework.ws:spring-xml
Version 5.0.2
org.apache.santuario:xmlsec
Version 4.0.4
org.apache.wss4j:wss4j-ws-security-dom
Version 4.0.1
org.jvnet.staxex:stax-ex
Version 2.1.0

Weekly Downloads

Info

Last Published
3 months ago
Created
10 years ago

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform