« Volver al listado

CVE-2026-40974

Estado: AnalizadaCrítica (9.8)—

Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra.

Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); Cassandra SSL auto-configuration. Versions that are no longer supported are also affected per vendor advisory.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N/PR:N sin UI sugiere red pública sin autenticación (T1190). CWE-295 (falta de verificación de hostname en SSL) permite ataque MITM (T1557.002). Acceso a datos de Cassandra tras interceptar conexión (T1005).

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-40974",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-40974",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-04-28T12:41:44.578319Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Spring",
          "product": "Spring Boot",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.0",
              "lessThan": "4.0.6",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.5.0",
              "lessThan": "3.5.14",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.4.0",
              "lessThan": "3.4.16",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.3.0",
              "lessThan": "3.3.19",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.7.0",
              "lessThan": "2.7.33",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-04-28T00:16:24.523",
  "references": [
    {
      "url": "https://spring.io/security/cve-2026-40974",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@vmware.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-295"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra.\n\nAffected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); Cassandra SSL auto-configuration. Versions that are no longer supported are also affected per vendor advisory."
    },
    {
      "lang": "es",
      "value": "La auto-configuración de Cassandra de Spring Boot no realiza la verificación de nombre de host al establecer una conexión SSL con Cassandra.\n\nAfectado: Spring Boot 4.0.0-4.0.5 (corrección 4.0.6), 3.5.0-3.5.13 (corrección 3.5.14), 3.4.0-3.4.15 (corrección 3.4.16), 3.3.0-3.3.18 (corrección 3.3.19), 2.7.0-2.7.32 (corrección 2.7.33); auto-configuración SSL de Cassandra. Las versiones que ya no son compatibles también están afectadas según el aviso del proveedor."
    }
  ],
  "lastModified": "2026-07-24T21:10:00.143",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2838ED31-53BD-4663-9532-8E0E968E4013",
              "versionEndExcluding": "2.7.33",
              "versionStartIncluding": "2.7.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28EE6470-24FD-49D1-A2F0-7A19B290A161",
              "versionEndExcluding": "3.3.19",
              "versionStartIncluding": "3.3.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "758A9E8F-0C52-43D9-8D84-69622B345A4E",
              "versionEndExcluding": "3.4.16",
              "versionStartIncluding": "3.4.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D23096A1-8269-46C5-9215-9098E87D0A24",
              "versionEndExcluding": "3.5.14",
              "versionStartIncluding": "3.5.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_boot:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "12A166C5-8B55-4BA3-AA8B-6024A257D441",
              "versionEndExcluding": "4.0.6",
              "versionStartIncluding": "4.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}