broadcom / spring_web_services
8 known vulnerabilities in broadcom spring_web_services.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2019-3773 | Medium | 4.1% | 9.8 | Spring Web Services, versions 2.4.3, 3.0.4, and older unsupported versions of al… | |
| CVE-2026-40999 | Medium | 0.4% | 8.6 | When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spri… | |
| CVE-2026-40998 | Medium | 0.4% | 8.2 | Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource i… | |
| CVE-2026-40994 | Medium | 0.2% | 8.2 | Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compl… | |
| CVE-2026-40997 | Low | 0.4% | 5.3 | Several Spring WS integration paths with Spring Security could surface detailed … | |
| CVE-2026-41000 | Low | 0.2% | 3.7 | Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache inst… | |
| CVE-2026-40995 | Low | 0.1% | 5.4 | X509AuthenticationProvider could issue a fully authenticated X509AuthenticationT… | |
| CVE-2026-40996 | Low | 0.1% | 4.8 | Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, over… |