VYPR

Maven package

org.springframework.boot/spring-boot-cassandra

pkg:maven/org.springframework.boot/spring-boot-cassandra

Vulnerabilities (3)

  • CVE-2026-40977MedApr 28, 2026
    affected >= 4.0.0, < 4.0.6fixed 4.0.6

    When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4

  • CVE-2026-40975MedApr 28, 2026
    affected >= 4.0.0, < 4.0.6fixed 4.0.6

    Values produced by ${random.value} are not suitable for use as secrets. ${random.uuid} is not affected. ${random.int} and ${random.long} should never be used for secrets as they are numeric values with a predictable range. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5

  • CVE-2026-40974MedApr 28, 2026
    affected >= 4.0.0, < 4.0.6fixed 4.0.6

    Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2