CVE-2026-40970: VMware Spring Boot

Medium severity, CVSS 6.8. EPSS: 0.2% chance of exploitation in the next 30 days.

When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory.

Affected products

  • VMware Spring Boot: from 4.0.0, before 4.0.6 (fixed in 4.0.6)

Published 2026-04-27. Last modified 2026-06-17.