Skip to content
cyberLOW2026-04-27 23:31 UTC

CVE-2026-40974 - Spring Boot Cassandra SSL Hostname Verification Bypass

CVE ID :CVE-2026-40974 Published : April 27, 2026, 11:31 p.m. | 30 minutes ago Description :Spring Boot's Cassandra auto-configuration does not perform hostname verification when establishing an SSL connection to Cassandra. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.

ORIGINAL SOURCE →via CVE Feed Latest
ADVERTISEMENT
⚡ STAY AHEAD

Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.

GET THE SUNDAY BRIEFING →

RELATED · cyber