CVE-2026-40981
published 2026-05-07CVE-2026-40981: When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.43%
35.2th percentile
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| log4j_2 | log4j | — | — |
| spring | spring_cloud_config | >= 3.1.0 < 3.1.14 | 3.1.14 |
| spring | spring_cloud_config | >= 4.1.0 < 4.1.10 | 4.1.10 |
| spring | spring_cloud_config | >= 4.2.0 < 4.2.7 | 4.2.7 |
| spring | spring_cloud_config | >= 4.3.0 < 4.3.3 | 4.3.3 |
| spring | spring_cloud_config | >= 5.0.0 < 5.0.3 | 5.0.3 |
| vmware | spring_cloud_config | >= 3.1.0 < 3.1.14 | 3.1.14 |
| vmware | spring_cloud_config | >= 4.1.0 < 4.1.10 | 4.1.10 |
| vmware | spring_cloud_config | >= 4.2.0 < 4.2.7 | 4.2.7 |
| vmware | spring_cloud_config | >= 4.3.0 < 4.3.3 | 4.3.3 |
| vmware | spring_cloud_config | >= 5.0.0 < 5.0.3 | 5.0.3 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Spring Cloud Config has an Authorization Bypass Through User-Controlled Key
ghsa·2026-05-07
CVE-2026-40981 [HIGH] CWE-639 Spring Cloud Config has an Authorization Bypass Through User-Controlled Key
Spring Cloud Config has an Authorization Bypass Through User-Controlled Key
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected fro
GHSA
GHSA-2mh5-3cw6-hrrq: When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposi
ghsa_unreviewed·2026-05-07
CVE-2026-40981 [HIGH] CWE-639 GHSA-2mh5-3cw6-hrrq: When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposi
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.
Red Hat
Spring Cloud Config: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects
vendor_redhat·2026-05-07·CVSS 7.5
CVE-2026-40981 [HIGH] CWE-1220 Spring Cloud Config: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects
Spring Cloud Config: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Clo
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
blogs_hackernews·2026-05-18·CVSS 6.1
CVE-2026-42897 [MEDIUM] ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted.
The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production incident. AI is speeding up vulnerability discovery, attackers are moving quickly, and old exposure still keeps paying off.
Patch the quiet risks first. Let’s g
Bugzilla
CVE-2026-40981 log4j: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects [fedora-all]
bugzilla·2026-06-08·CVSS 7.5
CVE-2026-40981 [HIGH] CVE-2026-40981 log4j: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects [fedora-all]
CVE-2026-40981 log4j: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40981 Spring Cloud Config: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects
bugzilla·2026-05-07·CVSS 7.5
CVE-2026-40981 [HIGH] CVE-2026-40981 Spring Cloud Config: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects
CVE-2026-40981 Spring Cloud Config: Spring Cloud Config: Information disclosure of secrets from unintended GCP projects
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or grea
2026-05-07
Published