Spring / Spring Cloud Config
10 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59315 | Spring Cloud Config Monitor Denial of Service | MEDIUM | 5.3 | Aug 27, 2026 |
| CVE-2026-47894 | Spring Cloud Config Server Native Environment Repository Exposure | HIGH | 7.5 | Aug 27, 2026 |
| CVE-2026-47837 | Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests | CRITICAL | 9.8 | Aug 26, 2026 |
| CVE-2026-47836 | Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN | HIGH | 8.1 | Aug 26, 2026 |
| CVE-2026-40981 | Spring Cloud Config: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects | HIGH | 7.5 | May 7, 2026 |
| CVE-2026-41002 | The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-che… | HIGH | 8.1 | May 7, 2026 |
| CVE-2026-41004 | Spring Cloud Config Server: Spring Cloud Config: Spring Cloud Config Server: Information disclosure via trace logging | MEDIUM | 4.4 | May 7, 2026 |
| CVE-2026-40982 | Spring Cloud Config: spring-cloud-config-server: Spring Cloud Config: Directory traversal allows arbitrary file access | CRITICAL | 9.1 | May 7, 2026 |
| CVE-2025-22232 | Spring Cloud Config Server May Not Use Vault Token Sent By Clients | MEDIUM | 5.3 | Apr 10, 2025 |
| CVE-2019-3799 | Directory Traversal with spring-cloud-config-server | MEDIUM | 6.5 | May 6, 2019 |
Showing 1 to 10 of 10 CVEs