CVE-2026-40991

Updated on 09 Jun 2026

Severity

5.9 Medium severity

Details

CVSS score
5.9
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:L

Overview

About vulnerability

SVG ImageDescription

When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests are next executed.

SVG ImageAffected Spring Products and Versions

Spring REST Docs:

  • 4.0.0
  • 3.0.0 - 3.0.5
  • 2.0.0.RELEASE - 2.0.8.RELEASE

Versions that are no longer supported are also affected.

SVG ImageMitigation

Users of affected versions should upgrade to the corresponding fixed version.

Affected version(s) Fix version Availability
4.0.x 4.0.1 OSS
4.0.x 4.0.0.1 Enterprise Support Only
3.0.x 3.0.6 OSS
3.0.x 3.0.5.1 Enterprise Support Only
2.0.x 2.0.9.RELEASE Enterprise Support Only

No further mitigation steps are necessary.

SVG ImageReferences

SVG ImageHistory

  • 2026-06-09: Initial vulnerability report published.

Details

SVG ImageDescription

When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests are next executed.

SVG ImageAffected Spring Products and Versions

Spring REST Docs:

  • 4.0.0
  • 3.0.0 - 3.0.5
  • 2.0.0.RELEASE - 2.0.8.RELEASE

Versions that are no longer supported are also affected.

SVG ImageMitigation

Users of affected versions should upgrade to the corresponding fixed version.

Affected version(s) Fix version Availability
4.0.x 4.0.1 OSS
4.0.x 4.0.0.1 Enterprise Support Only
3.0.x 3.0.6 OSS
3.0.x 3.0.5.1 Enterprise Support Only
2.0.x 2.0.9.RELEASE Enterprise Support Only

No further mitigation steps are necessary.

SVG ImageReferences

SVG ImageHistory

  • 2026-06-09: Initial vulnerability report published.