CVE-2026-40982
published 2026-05-07CVE-2026-40982: Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker…
PriorityP261critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.73%
50.4th percentile
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| log4j_2 | log4j | — | — |
| spring | spring_cloud_config | >= 3.1.0 < 3.1.14 | 3.1.14 |
| spring | spring_cloud_config | >= 4.1.0 < 4.1.10 | 4.1.10 |
| spring | spring_cloud_config | >= 4.2.0 < 4.2.7 | 4.2.7 |
| spring | spring_cloud_config | >= 4.3.0 < 4.3.3 | 4.3.3 |
| spring | spring_cloud_config | >= 5.0.0 < 5.0.3 | 5.0.3 |
| vmware | spring_cloud_config | >= 3.1.0 < 3.1.14 | 3.1.14 |
| vmware | spring_cloud_config | >= 4.1.0 < 4.1.10 | 4.1.10 |
| vmware | spring_cloud_config | >= 4.2.0 < 4.2.7 | 4.2.7 |
| vmware | spring_cloud_config | >= 4.3.0 < 4.3.3 | 4.3.3 |
| vmware | spring_cloud_config | >= 5.0.0 < 5.0.3 | 5.0.3 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect directory traversal attempts targeting the spring-cloud-config-server module by monitoring for specially crafted URLs containing path traversal sequences (e.g., ../) in requests to the config server endpoint. ↗
- →Monitor the spring-cloud-config-server module for requests that result in access to arbitrary text and binary files outside the intended configuration directory, which may indicate successful exploitation. ↗
- →Scope investigation of exploitation to the service account under which the Spring Cloud Config server operates, as successful exploitation is limited to that account's file access permissions. ↗
- ·Affected versions span multiple release trains: 3.1.0–3.1.13, 4.1.0–4.1.9, 4.2.0–4.2.6, 4.3.0–4.3.2, and 5.0.0–5.0.2. Detection and patching scope should cover all these branches. ↗
- ·No mitigation is available from Red Hat; patching to a fixed version is the only remediation path. ↗
- ·The vulnerability is tracked under the spring-cloud-config-server component in Red Hat JBoss Enterprise Application Platform Expansion Pack and also associated with the log4j:2/log4j package in RHEL 8 — verify which component is actually deployed in your environment. ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Spring Cloud Config: spring-cloud-config-server: Spring Cloud Config: Directory traversal allows arbitrary file access
vendor_redhat·2026-05-07·CVSS 9.1
CVE-2026-40982 [CRITICAL] CWE-22 Spring Cloud Config: spring-cloud-config-server: Spring Cloud Config: Directory traversal allows arbitrary file access
Spring Cloud Config: spring-cloud-config-server: Spring Cloud Config: Directory traversal allows arbitrary file access
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected
GHSA
GHSA-6g23-24mc-hx6x: Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module
ghsa_unreviewed·2026-05-07
CVE-2026-40982 [CRITICAL] CWE-22 GHSA-6g23-24mc-hx6x: Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 throu
GHSA
Spring Cloud Config vulnerable to Path Traversal
ghsa·2026-05-07
CVE-2026-40982 [CRITICAL] CWE-22 Spring Cloud Config vulnerable to Path Traversal
Spring Cloud Config vulnerable to Path Traversal
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Sp
No detection rules found.
No public exploits indexed.
Hackernews
⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
blogs_hackernews·2026-05-18·CVSS 6.1
CVE-2026-42897 [MEDIUM] ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted.
The pattern is clear. One weak dependency can leak keys. One leaked key can open cloud access. One cloud foothold can become a production incident. AI is speeding up vulnerability discovery, attackers are moving quickly, and old exposure still keeps paying off.
Patch the quiet risks first. Let’s g
Bugzilla
CVE-2026-40982 log4j: Spring Cloud Config: Directory traversal allows arbitrary file access [fedora-all]
bugzilla·2026-06-08·CVSS 9.1
CVE-2026-40982 [CRITICAL] CVE-2026-40982 log4j: Spring Cloud Config: Directory traversal allows arbitrary file access [fedora-all]
CVE-2026-40982 log4j: Spring Cloud Config: Directory traversal allows arbitrary file access [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-40982 Spring Cloud Config: spring-cloud-config-server: Spring Cloud Config: Directory traversal allows arbitrary file access
bugzilla·2026-05-07·CVSS 9.1
CVE-2026-40982 [CRITICAL] CVE-2026-40982 Spring Cloud Config: spring-cloud-config-server: Spring Cloud Config: Directory traversal allows arbitrary file access
CVE-2026-40982 Spring Cloud Config: spring-cloud-config-server: Spring Cloud Config: Directory traversal allows arbitrary file access
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config
2026-05-07
Published