PatchSiren cyber security CVE debrief
CVE-2026-40991 Spring CVE debrief
CVE-2026-40991 is a vulnerability in Spring REST Docs that allows for an XXE (XML External Entity) injection attack. When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests are next executed. This vulnerability affects Spring REST Docs versions 4.0.0, 3.0.0 through 3.0.5, and 2.0.0.RELEASE through 2.0.8.RELEASE.
- Vendor
- Spring
- Product
- Spring REST Docs
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-10
- Original CVE updated
- 2026-07-17
- Advisory published
- 2026-06-10
- Advisory updated
- 2026-07-17
Who should care
Users of Spring REST Docs versions 4.0.0, 3.0.0-3.0.5, and 2.0.0.RELEASE-2.0.8.RELEASE should be aware of this vulnerability and take steps to mitigate it.
Technical summary
The vulnerability has a CVSS score of 5.9 and a severity of MEDIUM. It requires the attacker to have access to the API or to trick the user into documenting a malicious API. The attack can be performed when the documentation-generating tests are executed.
Defensive priority
MEDIUM
Recommended defensive actions
- Upgrade to a non-vulnerable version of Spring REST Docs.
- Use a secure API documentation tool.
- Validate and sanitize user input.
Evidence notes
The CVE record [cve-org] and NVD detail [nvd] provide information on the vulnerability. The source reference [ref-4] provides additional details on the vulnerability and its fix.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-40991 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-40991
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-40991 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-40991
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://spring.io/security/cve-2026-40991
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.