CVE-2026-40969
Spring gRPC AuthenticationException message reflected to remote client
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
The raw message of every server-side AuthenticationException is returned to the unauthenticated remote caller in the gRPC status description. This allows an attacker to obtain information about the authentication failure, which may be useful for further attacks. Affected versions: Spring gRPC: 1.0.0 - 1.0.2 (fixed in 1.0.3). Older, unsupported versions are also affected.
| CWE | CWE-209 |
| Vendor | spring |
| Product | spring grpc |
| Ecosystems | |
| Industries | TechnologyEnterprise |
| Published | Apr 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for spring spring grpc
Be the first to know when new low vulnerabilities affecting spring spring grpc are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
Spring / Spring gRPC
1.0.0 < 1.0.3