Back to CVE List

CVE-2026-40991

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
5.9 / 10
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L

Vulnerability Description

When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests are next executed.

Affected versions:
Spring REST Docs 4.0.0; 3.0.0 through 3.0.5; 2.0.0.RELEASE through 2.0.8.RELEASE.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-611
Source
NVD
Vendor
Spring
Product
Spring REST Docs

External References

Discussion (0)

Add Comment

No comments yet. Be the first!