Broadcom Spring Web Services — known CVE vulnerabilities
Every CVE whose affected-product data names Broadcom Spring Web Services, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (8)
CVE-2019-3773 — CVSS 9.8 (critical): Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of all three projects, were susceptible to XML External Entity…
CVE-2026-40999 — CVSS 8.6 (high): When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured…
CVE-2026-40998 — CVSS 8.2 (high): Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML…
CVE-2026-40994 — CVSS 8.2 (high): Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP…
CVE-2026-40995 — CVSS 5.4 (medium): X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails…
CVE-2026-40997 — CVSS 5.3 (medium): Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user…
CVE-2026-40996 — CVSS 4.8 (medium): Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation…
CVE-2026-41000 — CVSS 3.7 (low): Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a…