CVE 3.7 LOW

Spring gRPC AuthenticationException message reflected to remote client_CVE-2026-40969

3.7 / 10
LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

Description

The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks.

Affected versions:
Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.

Basic Information

ID CVE-2026-40969
Source vmware
Published Apr 28, 2026 at 14:54

Affected Product

Vendor Spring
Product Spring gRPC
Version 1.0.0
Affected Versions Spring Spring gRPC 1.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.