4.7
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H
Description
When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); PID file / symlink behavior (`ApplicationPidFileWriter`). Versions that are no longer supported are also affected per vendor advisory.
Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); PID file / symlink behavior (`ApplicationPidFileWriter`). Versions that are no longer supported are also affected per vendor advisory.
Basic Information
ID
CVE-2026-40977
Source
vmware
Published
Apr 27, 2026 at 23:36
Affected Product
Vendor
Spring
Product
Spring Boot
Version
4.0.0
Affected Versions
Spring Spring Boot 4.0.0
Spring Spring Boot 3.5.0
Spring Spring Boot 3.4.0
Spring Spring Boot 3.3.0
Spring Spring Boot 2.7.0
Spring Spring Boot 3.5.0
Spring Spring Boot 3.4.0
Spring Spring Boot 3.3.0
Spring Spring Boot 2.7.0