Spring cloud config
This hub aggregates every CVE we track for Spring cloud config, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
OSS Librariesother
10
CVEs tracked
1
Critical
4
High
1
In CISA KEV
Severity distribution
MEDIUM5HIGH4CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
1
0
0
0
0
0
0
0
0
0
0
1
0
4
0
2024-072026-06
Latest CVEs
The 10 most recently published vulnerabilities affecting Spring cloud config.
- CVE-2026-40981When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring...7.5
- CVE-2026-41002The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Sprin...7.2
- CVE-2026-41004When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgr...4.4
- CVE-2026-40982Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially c...9.1
- CVE-2026-22739Spring Cloud Config Profile Substitution Can Allow Unintended Access To Files And Enable SSRF Attacks8.6
- CVE-2025-22232Spring Cloud Config Server May Not Use Vault Token Sent By Clients5.3
- CVE-2023-20859In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attem...5.5
- CVE-2020-5410Directory Traversal with spring-cloud-config-serverKEV7.5
- CVE-2020-5405Directory Traversal with spring-cloud-config-server6.5
- CVE-2019-3799Directory Traversal with spring-cloud-config-server6.5
Product normalization is registry-driven with AI assist and human review. How it works