SCA: security update for org.springframework.ws:spring-ws-core (GHSA-whpp-xv3h-rwxf)

high Tenable Self-Hosted Container Security Plugin ID 446228

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate
outbound connections through configured WebServiceMessageSender instances to destinations taken directly
from request headers without verifying that those destinations are safe to connect to. Affected versions:
Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
(CVE-2026-40999)

Solution

Update the org.springframework.ws:spring-ws-core library and its related packages to version 4.1.4 or later.

See Also

https://github.com/advisories/GHSA-whpp-xv3h-rwxf

Plugin Details

Severity: High

ID: 446228

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/22/2026

Updated: 8/22/2026

Risk Information

VPR

Risk Factor: Low

Score: 3.3

Percentile: 51

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2026-40999

CVSS v3

Risk Factor: High

Base Score: 8.6

Temporal Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 6/11/2026

Vulnerability Publication Date: 6/11/2026

Reference Information

CVE: CVE-2026-40999

cwe: CWE-918