Security scanners or the official Spring Security advisory may identify CVE-2026-40992 as a potential vulnerability. Customers utilizing Spring Boot 2.7.x have requested clarification on whether this branch is affected and why no recent patches have been released for this line.
CVE-2026-40992 is related to an information disclosure vulnerability specifically within the SSL support for JavaMail (mail sender).
Investigation by the Spring engineering team has confirmed that this vulnerability does not apply to the Spring Boot 2.7 branch for the following reasons:
Spring Boot 2.7.x is NOT affected by CVE-2026-40992. No action is required to mitigate this specific CVE for applications on the 2.7.x line.