{"id":"GHSA-3jh5-rr2q-xfv7","summary":"Valtimo has sensitive data exposure through HTTP request/response logging in LoggingRestClientCustomizer","details":"### Summary\n\nThe `LoggingRestClientCustomizer` in the `web` module automatically intercepts all outgoing HTTP calls made via Spring's `RestClient` and logs the full request body, response body, and response headers. When an error response is received, this information is included in the thrown `HttpClientErrorException` message, which is logged at ERROR level by Spring's default exception handling — regardless of the application's DEBUG log level setting.\n\n### Impact\n\nThe logged data can contain highly sensitive information including:\n- Authentication credentials (JWT tokens, API keys, OAuth tokens) in request bodies or response headers\n- Personal data (BSN, email addresses, case details) in request/response bodies\n- Session tokens in `Set-Cookie` response headers\n\nThis data is exposed to:\n- Anyone with access to application logs (stdout/log files)\n- Users with access to logging aggregation tools (e.g. Grafana/Loki)\n- Any Valtimo user with the admin role, through the built-in logging module (since Valtimo 12.5.0)\n\nLeaked authentication credentials could be used to impersonate the Valtimo application against the target external API (e.g. ZGW services), compromising that API's security boundary.\n\nRelated: GHSA-hfrg-mcvw-8mch (similar sensitive data exposure in InboxHandlingService)\n\n### Affected Code\n\n`com.ritense.valtimo.web.logging.LoggingRestClientCustomizer#intercept` in the `web` module.\n\n### Patched Versions\n\nThe vulnerability is fixed in:\n- **12.33.0** (v12 release line) — see PR #600\n- **13.26.0** (v13 release line) — see PR #599\n\nThe fix removes the request/response report, headers, and response body from the `HttpClientErrorException` constructor; only the HTTP status code and status text remain. The full request/response report is still emitted at DEBUG level (disabled in production).\n\n### Mitigation\n\nIf you cannot upgrade to a patched version immediately, consider:\n- Restricting access to application logs and the Valtimo logging module\n- Adjusting the log level for `com.ritense.valtimo.web.logging` to WARN or higher (note: this only mitigates the DEBUG logging path; error responses still leak data via the exception message)","aliases":["CVE-2026-44516"],"modified":"2026-09-10T03:51:04.512717160Z","published":"2026-05-11T16:11:06Z","database_specific":{"github_reviewed_at":"2026-05-11T16:11:06Z","nvd_published_at":"2026-05-14T17:16:23Z","cwe_ids":["CWE-532"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/valtimo-platform/valtimo/security/advisories/GHSA-3jh5-rr2q-xfv7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44516"},{"type":"WEB","url":"https://github.com/valtimo-platform/valtimo/pull/599"},{"type":"WEB","url":"https://github.com/valtimo-platform/valtimo/pull/600"},{"type":"PACKAGE","url":"https://github.com/valtimo-platform/valtimo"}],"affected":[{"package":{"name":"com.ritense.valtimo:web","ecosystem":"Maven","purl":"pkg:maven/com.ritense.valtimo/web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"12.4.0"},{"fixed":"12.33.0"}]}],"versions":["12.10.0.RELEASE","12.10.1.RELEASE","12.10.2.RELEASE","12.11.0.RELEASE","12.12.0.RELEASE","12.13.0.RELEASE","12.13.1.RELEASE","12.14.0.RELEASE","12.14.1.RELEASE","12.15.1.RELEASE","12.16.0.RELEASE","12.16.1.RELEASE","12.17.0.RELEASE","12.17.1.RELEASE","12.18.0.RELEASE","12.19.0.RELEASE","12.20.0.RELEASE","12.20.1.RELEASE","12.21.0.RELEASE","12.21.1.RELEASE","12.22.0.RELEASE","12.23.0.RELEASE","12.23.1.RELEASE","12.24.0.RELEASE","12.25.0.RELEASE","12.26.0.RELEASE","12.27.0.RELEASE","12.28.0.RELEASE","12.28.1.RELEASE","12.29.0.RELEASE","12.30.0.RELEASE","12.31.0.RELEASE","12.32.0.RELEASE","12.4.0.RELEASE","12.4.1.RELEASE","12.4.3.RELEASE","12.5.0.RELEASE","12.5.1.RELEASE","12.6.0.RELEASE","12.6.1.1.RC","12.6.1.RELEASE","12.7.0.RELEASE","12.7.1.RELEASE","12.7.2.RELEASE","12.7.3.RELEASE","12.8.0.RELEASE","12.9.0.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-3jh5-rr2q-xfv7/GHSA-3jh5-rr2q-xfv7.json"}},{"package":{"name":"com.ritense.valtimo:web","ecosystem":"Maven","purl":"pkg:maven/com.ritense.valtimo/web"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"13.0.0"},{"fixed":"13.26.0"}]}],"versions":["13.0.0.RELEASE","13.0.1.RELEASE","13.0.2.RELEASE","13.1.0.RELEASE","13.1.1.RELEASE","13.1.2.RELEASE","13.1.3.RELEASE","13.10.0.RELEASE","13.11.0.RELEASE","13.12.0.RELEASE","13.13.0.RELEASE","13.14.0.RELEASE","13.15.0.RELEASE","13.16.0.RELEASE","13.17.0.RELEASE","13.17.1.RELEASE","13.18.0.RELEASE","13.19.0.RELEASE","13.2.0.RELEASE","13.2.1.RELEASE","13.20.0.RELEASE","13.21.0.RELEASE","13.22.0.RELEASE","13.23.0.RELEASE","13.24.0.RELEASE","13.24.1.RELEASE","13.25.0.RELEASE","13.25.1.RELEASE","13.3.0.RELEASE","13.4.0.RELEASE","13.4.1.RELEASE","13.4.2.RELEASE","13.5.0.RELEASE","13.5.1.RELEASE","13.6.0.RELEASE","13.7.0.RELEASE","13.8.0.RELEASE","13.9.0.RELEASE","13.9.1.RELEASE"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/05/GHSA-3jh5-rr2q-xfv7/GHSA-3jh5-rr2q-xfv7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N"}]}