Home

Description

When an application is configured to use `ApplicationPidFileWriter`, a local attacker with write access to the PID file's location can corrupt one file on the host each time the application is started. Affected: Spring Boot 4.0.0–4.0.5 (fix 4.0.6), 3.5.0–3.5.13 (fix 3.5.14), 3.4.0–3.4.15 (fix 3.4.16), 3.3.0–3.3.18 (fix 3.3.19), 2.7.0–2.7.32 (fix 2.7.33); PID file / symlink behavior (`ApplicationPidFileWriter`). Versions that are no longer supported are also affected per vendor advisory.

PUBLISHED Reserved 2026-04-16 | Published 2026-04-27 | Updated 2026-04-28 | Assigner vmware




MEDIUM: 4.7CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:H

Problem types

CWE-59: Improper Link Resolution Before File Access

Product status

Default status
unaffected

4.0.0 (custom) before 4.0.6
affected

3.5.0 (custom) before 3.5.14
affected

3.4.0 (custom) before 3.4.16
affected

3.3.0 (custom) before 3.3.19
affected

2.7.0 (custom) before 2.7.33
affected

References

spring.io/security/cve-2026-40977

cve.org (CVE-2026-40977)

nvd.nist.gov (CVE-2026-40977)

Download JSON