๐Ÿ” CVE Alert

CVE-2026-9370

LOW 3.7

ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
7th

A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeySaltGenerator of the file jasypt-spring-boot/src/main/java/com/ulisesbocchio/jasyptspringboot/encryptor/SimpleGCMConfig.java of the component Password Hash Handler. Executing a manipulation can lead to use of a one-way hash with a predictable salt. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-760 CWE-759
Vendor ulisesbocchio
Product jasypt-spring-boot
Published May 24, 2026
Last Updated May 29, 2026
Stay Ahead of the Next One

Get instant alerts for ulisesbocchio jasypt-spring-boot

Be the first to know when new low vulnerabilities affecting ulisesbocchio jasypt-spring-boot are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

ulisesbocchio / jasypt-spring-boot
3.0.0 3.0.1 3.0.2 3.0.3 3.0.4 3.0.5 4.0.0 4.0.1 4.0.2 4.0.3 4.0.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/365333 vuldb.com: https://vuldb.com/vuln/365333/cti vuldb.com: https://vuldb.com/submit/813198 github.com: https://github.com/ulisesbocchio/jasypt-spring-boot/issues/431 github.com: https://github.com/dntyfate/cve/issues/3 github.com: https://github.com/ulisesbocchio/jasypt-spring-boot/

Credits

๐Ÿ” zyhhoward (VulDB User) VulDB CNA Team