CVE-2026-40969

The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks. Affected versions: Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.
References
Link Resource
https://spring.io/security/cve-2026-40969 Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:vmware:spring_grpc:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-28 15:16

Updated : 2026-06-17 10:45


NVD link : CVE-2026-40969

Mitre link : CVE-2026-40969

CVE.ORG link : CVE-2026-40969


JSON object : View

Products Affected

vmware

  • spring_grpc
CWE
CWE-209

Generation of Error Message Containing Sensitive Information