CVE-2026-40970 PUBLISHED

Assigner: vmware
Reserved: 16.04.2026 Published: 27.04.2026 Updated: 27.04.2026

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server.

Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CVSS Score: 5

Product Status

Vendor Spring
Product Spring Boot
Versions Default: unaffected
  • affected from 4.0.0 to 4.0.6 (excl.)

References

Problem Types

  • CWE-295: Improper Certificate Validation CWE