CVE-2026-9370
LOWulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
Title source: cnaDescription
A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeySaltGenerator of the file jasypt-spring-boot/src/main/java/com/ulisesbocchio/jasyptspringboot/encryptor/SimpleGCMConfig.java of the component Password Hash Handler. Executing a manipulation can lead to use of a one-way hash with a predictable salt. The attack can be launched remotely. The attack requires a high level of complexity. The exploitation appears to be difficult. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.
References (6)
Core 6
Core References
Vdb Entry, Technical Description vdb-entry
technical-description
VDB-365333 | ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGenerator hash predictable salt
https://vuldb.com/vuln/365333
Signature, Permissions Required signature
permissions-required
VDB-365333 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/365333/cti
Third Party Advisory third-party-advisory
Submit #813198 | Ulises Bocchio jasypt-spring-boot 3.0.0 to 4.0.4 Cryptographic Issues
https://vuldb.com/submit/813198
Issue Tracking issue-tracking
https://github.com/ulisesbocchio/jasypt-spring-boot/issues/431
Exploit exploit
issue-tracking
https://github.com/dntyfate/cve/issues/3
Product product
https://github.com/ulisesbocchio/jasypt-spring-boot/
Scores
CVSS v3
3.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R
Details
CWE
CWE-759
CWE-760
Status
published
Products (11)
ulisesbocchio/jasypt-spring-boot
3.0.0
ulisesbocchio/jasypt-spring-boot
3.0.1
ulisesbocchio/jasypt-spring-boot
3.0.2
ulisesbocchio/jasypt-spring-boot
3.0.3
ulisesbocchio/jasypt-spring-boot
3.0.4
ulisesbocchio/jasypt-spring-boot
3.0.5
ulisesbocchio/jasypt-spring-boot
4.0.0
ulisesbocchio/jasypt-spring-boot
4.0.1
ulisesbocchio/jasypt-spring-boot
4.0.2
ulisesbocchio/jasypt-spring-boot
4.0.3
... and 1 more
Published
May 24, 2026
Tracked Since
May 24, 2026