Insecure Temporary File Affecting org.springframework.boot:spring-boot-artemis package, versions [4.0.0-M1, 4.0.7)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.09% (1st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGSPRINGFRAMEWORKBOOT-18324165
  • published27 Jul 2026
  • disclosed10 Jun 2026
  • creditYu Bao

Introduced: 10 Jun 2026

CVE-2026-41001  (opens in a new tab)
CWE-377  (opens in a new tab)

How to fix?

Upgrade org.springframework.boot:spring-boot-artemis to version 4.0.7 or higher.

Overview

org.springframework.boot:spring-boot-artemis is a

Affected versions of this package are vulnerable to Insecure Temporary File. via the default data directory configuration in ArtemisEmbeddedConfigurationFactory. A local attacker can tamper with or redirect the embedded Artemis broker's data storage by pre-creating the predictable data directory or replacing it with a symlink before the application starts. This may allow unauthorized access to message data, injection of malicious messages, or further compromise through processing of attacker-controlled broker data.

Note: This is only exploitable by an attacker with local access to the host system before the application initializes the embedded broker.

CVSS Base Scores

version 4.0
version 3.1