Medium severity5.0NVD Advisory· Published Jun 11, 2026· Updated Jun 11, 2026
CVE-2026-40992
CVE-2026-40992
Description
Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=true, are not affected.
Affected versions: Spring Boot 4.0.0 through 4.0.6; 3.5.0 through 3.5.14; 3.4.0 through 3.4.16.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.springframework.boot:spring-boot-starter-mailMaven | >= 4.0.0, < 4.0.7 | 4.0.7 |
org.springframework.boot:spring-boot-starter-mailMaven | >= 3.5.0, < 3.5.15 | 3.5.15 |
org.springframework.boot:spring-boot-starter-mailMaven | >= 3.4.0, <= 3.4.16 | — |
Affected products
2- Range: (>=3.4.0, <=3.4.16) || (>=3.5.0, <=3.5.14) || (>=4.0.0, <=4.0.6)
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-9wxp-w4px-32vhghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-40992ghsaADVISORY
- spring.io/security/cve-2026-40992nvdWEB
News mentions
0No linked articles in our index yet.