Maven package
org.springframework.restdocs/spring-restdocs-restassured
pkg:maven/org.springframework.restdocs/spring-restdocs-restassured
Vulnerabilities (1)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-40991 | Med | 5.9 | >= 4.0.0, < 4.0.1 | 4.0.1 | Jun 10, 2026 | When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests |
- affected >= 4.0.0, < 4.0.1fixed 4.0.1
When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests