VYPR

Web Services

by Spring Projects

CVEs (1)

  • CVE-2026-40998HigJun 11, 2026
    risk 0.53cvss 8.2epss

    Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath…