spring.io Critical Vulnerabilities in Spring Boot's SSL Configuration for Elasticsearch and RabbitMQ
Article Content
- •CVE-2026-40970 and CVE-2026-40971 disable TLS hostname verification in Spring Boot.
- •Affected systems include Elasticsearch and RabbitMQ when using SSL bundles.
- •Immediate upgrades to fixed versions are required to mitigate these vulnerabilities.
Two critical vulnerabilities have been identified in Spring Boot's auto-configuration for Elasticsearch and RabbitMQ. CVE-2026-40970 affects Elasticsearch, while CVE-2026-40971 impacts RabbitMQ. Both vulnerabilities occur when configured to use an SSL bundle, leading to the disabling of TLS hostname verification during connections to their respective servers. Users of affected versions are advised to upgrade to fixed versions immediately. The vulnerabilities were reported by Yu Bao from PayPal. No further mitigation steps are necessary beyond upgrading. The issues could potentially expose users to man-in-the-middle attacks if exploited. The vulnerabilities were disclosed on April 27, 2026.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-40970 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…
Critical Citrix NetScaler Vulnerabilities Actively Exploited in Finland The National Cyber Security Centre Finland (NCSC-FI) issued an alert regarding critical vulnerabilities in Citrix NetScaler ADC and Gateway products, specifically CVE-2026-88771 and CVE-2026-88772, which are being actively exploited in Finland. These vulnerabilities allow attackers to execute remote code without…