CVE-2026-40999 - Spring WS SSRF via unvalidated WS-Addressing reply destinations
CVE ID :CVE-2026-40999 Published : June 11, 2026, 5:04 a.m. | 1 hour, 59 minutes ago Description :When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken...