GHSA-6rpq-6vv2-5222
MODERATECVE-2026-40991When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a malicious API can perform an XXE injection attack when the documentation-generating tests are next executed.
- Affected
- = 4.0.0
- Fixed in
- 4.0.1
- Weakness
- CWE-611
- Published
- 2026-06-10
- Source
- github