Root has patched CVE-2026-40976 in the io.root.org.springframework.boot:spring-boot package for Root:Maven. Multiple fixed versions available.
{ "source": "Root", "severity": "HIGH", "distro": "maven", "distro_version": "" }
"root.io.2"
"https://api.root.io/external/osv/ROOT-APP-MAVEN-CVE-2026-40976.json"
true
2.0
"4.0.5"
[ "4.0.5-root.io.1", "4.0.5-root.io.2" ]
""
1.0
"4.0.5-aikido.2"
[ "4.0.5-aikido.2" ]