Report: CVE-2026-40970 - Spring Boot Elasticsearch SSL hostname verification bypass

Report: CVE-2026-40970 - Spring Boot Elasticsearch SSL hostname verification bypass

CVE ID :CVE-2026-40970 Published : April 27, 2026, 7:16 p.m. | 41 minutes ago Description :When configured to use an SSL bundle, Spring Boot's Elasticsearch auto-configuration does not perform hostname verification when connecting to the Elasticsearch server. Affected: Spring Boot 4.0.0–4.0.5; upgrade to 4.0.6 or later per vendor advisory. Severity: 5.0 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
April 27, 2026
Affected Product: Elasticsearch