CVE-2026-40998Broadcom · Spring_web_services
Vulnerability data via NVD (ingested)
Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior instead of Spring's hardened parser configuration. Applications that evaluate XPath against untrusted XML payloads could therefore be exposed to XML External Entity (XXE) style attacks. Affected versions: Spring Web Services 5.0.0 through 5.0.1; 4.1.0 through 4.1.3; 4.0.0 through 4.0.18; 3.1.0 through 3.1.8.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common). Live host counts are a Premium feature.
vuln:CVE-2026-40998product:"Broadcom Spring Web Services"http.html:"Spring Web Services"More intel sources (5)
vuln:CVE-2026-40998vulnerabilities.cve_id: CVE-2026-40998CVE-2026-40998CVE-2026-40998"CVE-2026-40998" exploit -site:nvd.nist.gov