Executive brief
Spring Boot is a popular framework used by developers to build Java-based web applications. A security flaw in its development tools (DevTools) could allow an attacker on the same network to guess a secret password by measuring how long the server takes to respond to different requests. If successful, the attacker could gain full control over the application, allowing them to modify its behavior or execute malicious code.
Technical details
A timing attack vulnerability (CWE-208) exists in the DevTools component of Spring Boot during the comparison of the remote secret. An attacker located on the same network (adjacent) can exploit observable timing discrepancies in the secret verification process to iteratively discover the correct secret. Once the secret is compromised, the attacker can use DevTools functionality to upload modified class files to the running application. This results in remote code execution (RCE) within the context of the application. The vulnerability is addressed in versions 4.0.6, 3.5.14, 3.4.16, 3.3.19, and 2.7.33.
Affected products
- VMware Spring Boot 4.0.0–4.0.5, 3.5.0–3.5.13, 3.4.0–3.4.15, 3.3.0–3.3.18, 2.7.0–2.7.32
Timeline
- 2026-04-27: advisory: Initial advisory published by VMware
- 2026-04-28: disclosed: NVD publication date