Spring Cloud Config Server: Spring Cloud Config: Spring Cloud Config Server: Information disclosure via trace logging
Published May 7, 2026
4.4
MEDIUMCVSS 3.1
EPSS 0.16%
Description
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.
Affected products
-
- Version 3.1.0StatusaffectedConstraints<3.1.14
- Version 4.1.0StatusaffectedConstraints<4.1.10
- Version 4.2.0StatusaffectedConstraints<4.2.7
- Version 4.3.0StatusaffectedConstraints<4.3.3
- Version 5.0.0StatusaffectedConstraints<5.0.3
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Spring | Spring Cloud Config | unaffected |
|
- ≥ 3.1.0 · < 3.1.14
- ≥ 4.1.0 · < 4.1.10
- ≥ 4.2.0 · < 4.2.7
- ≥ 4.3.0 · < 4.3.3
- ≥ 5.0.0 · < 5.0.3
No data.
Red Hat Enterprise Linux 8
log4j:2/log4j
Fix deferred
Red Hat JBoss Enterprise Application Platform Expansion Pack
spring-cloud-config-server
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Fix deferred | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | spring-cloud-config-server | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-41004 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2467637 Issue Tracking
- https://github.com/advisories/GHSA-j6hh-h3cf-c2hf Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-41004
- https://spring.io/security/cve-2026-41004 Vendor Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-41004
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-41004 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2467637 | Issue Tracking | |
| https://github.com/advisories/GHSA-j6hh-h3cf-c2hf | Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-41004 | ||
| https://spring.io/security/cve-2026-41004 | Vendor Advisory | |
| https://www.cve.org/CVERecord?id=CVE-2026-41004 |
Change history (0)
No recorded changes yet.