CVE-2026-40971
CVE-2026-40971: 2 tracked advisory records across NetApp, VMware. Compare vendor sources.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
NetApp
1 advisory- Advisory severityCritical9.1
Critical [CVE-2026-40971] Spring Boot Vulnerability in NetApp Products
NTAP-20260626-0018Source published Source updated
Multiple NetApp products incorporate Spring Boot. Spring Boot versions 3.5.0 prior to 3.5.14 and 4.0.0 prior to 4.0.6 are susceptible to a vulnerability which when successfully exploited could lead to disclosure of sensitive information or addition or modification of data. NetApp reports that one or more additional products remain under investigation; review the canonical advisory for current status. NetApp states there is no workaround available at this time.
- Affected products in this advisory
- No product details extracted. Check the source bulletin.
- Source-reported affected versions
- 3.5.0
- 3.5.14
- 4.0.0
- 4.0.6
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
VMware
1 advisory- Advisory severityMedium5.0
Medium [CVE-2026-40971] When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification
CVE-2026-40971Source published Source updated
When configured to use an SSL bundle, Spring Boot's RabbitMQ auto-configuration does not perform hostname verification when connecting to the RabbitMQ broker. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14) per vendor advisory.
- Related products — impact not confirmed
- Spring Boot
- RabbitMQ
- Source-reported affected versions
- 4.0.0
- 4.0.5
- 4.0.6
- 3.5.0
2 more entries in the full advisory.
- Source-reported fixed versions
- No fixed-version detail extracted. This does not mean no fix exists.
- Mitigation guidance
- No mitigation guidance extracted; consult the source.
Android app · Google Play
Turn CVE research into alerts on your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.