Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CVE-2026-40999 is a Server-Side Request Forgery (SSRF) vulnerability in Spring Web Services that allows an unauthenticated attacker to manipulate outbound HTTP/HTTPS connections from your servers by injecting malicious WS-Addressing headers into SOAP requests. Any organization running Spring WS 3.1.x through 5.0.x with WS-Addressing enabled is exposed. The primary business risk is unauthorized access to internal network resources, cloud metadata endpoints, and internal APIs that the application server can reach.

Author

Tech Jacks Solutions