Vulnerability Description
When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests are next executed. Affected versions: Spring REST Docs 4.0.0; 3.0.0 through 3.0.5; 2.0.0.RELEASE through 2.0.8.RELEASE.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Spring Rest Docs | >= 2.0.0, < 2.0.9 |
Related Weaknesses (CWE)
References
- https://spring.io/security/cve-2026-40991Vendor Advisory
FAQ
What is CVE-2026-40991?
CVE-2026-40991 is a vulnerability with a CVSS score of 5.9 (MEDIUM). When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious...
How severe is CVE-2026-40991?
CVE-2026-40991 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-40991?
Check the references section above for vendor advisories and patch information. Affected products include: Broadcom Spring Rest Docs.