5 Total advisories
5 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.springframework.ws:spring-ws-security is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.2
CVE-2026-40994
Spring Web Services: Wss4jSecurityInterceptor disables WS-I BSP validation by default
MEDIUM 5.4
CVE-2026-40995
Spring Web Services: X.509 authentication bypasses Spring Security account checks
LOW 3.7
CVE-2026-41000
Spring Web Services: WSS4J validation does not use configured replay cache
MEDIUM 4.8
CVE-2026-40996
Spring Web Services: Inbound WS-Security allows RSA PKCS#1 v1.5 key transport by default
MEDIUM 5.3
CVE-2026-40997
Spring Web Services: SOAP security faults leak Spring Security account state
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes