Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could therefore be exposed to XML External Entity (XXE) style attacks. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
References
History

Fri, 04 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Broadcom
Broadcom spring Web Services
CPEs cpe:2.3:a:broadcom:spring_web_services:*:*:*:*:*:*:*:*
Vendors & Products Broadcom
Broadcom spring Web Services

Thu, 11 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 11 Jun 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring spring Web Services
Vendors & Products Spring
Spring spring Web Services

Thu, 11 Jun 2026 06:45:00 +0000

Type Values Removed Values Added
Description Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could therefore be exposed to XML External Entity (XXE) style attacks. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
Title Jaxp13 XPath XXE via StreamSource and SAXSource
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published: 2026-06-11T05:04:12.565Z

Updated: 2026-06-23T19:51:18.888Z

Reserved: 2026-04-16T02:19:12.970Z

Link: CVE-2026-40998

cve-icon Vulnrichment

Updated: 2026-06-11T14:53:37.975Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-11T07:16:27.787

Modified: 2026-09-04T18:19:26.960

Link: CVE-2026-40998

cve-icon Redhat

No data.