CVE-2026-41004
published 2026-05-07CVE-2026-41004: When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from…
PriorityP420medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.17%
6.4th percentile
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| log4j_2 | log4j | — | — |
| spring | spring_cloud_config | >= 3.1.0 < 3.1.14 | 3.1.14 |
| spring | spring_cloud_config | >= 4.1.0 < 4.1.10 | 4.1.10 |
| spring | spring_cloud_config | >= 4.2.0 < 4.2.7 | 4.2.7 |
| spring | spring_cloud_config | >= 4.3.0 < 4.3.3 | 4.3.3 |
| spring | spring_cloud_config | >= 5.0.0 < 5.0.3 | 5.0.3 |
| vmware | spring_cloud_config | >= 3.1.0 < 3.1.14 | 3.1.14 |
| vmware | spring_cloud_config | >= 4.1.0 < 4.1.10 | 4.1.10 |
| vmware | spring_cloud_config | >= 4.2.0 < 4.2.7 | 4.2.7 |
| vmware | spring_cloud_config | >= 4.3.0 < 4.3.3 | 4.3.3 |
| vmware | spring_cloud_config | >= 5.0.0 < 5.0.3 | 5.0.3 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Spring Cloud Config Server Logged Sensitive Information
ghsa·2026-05-07
CVE-2026-41004 [MEDIUM] CWE-532 Spring Cloud Config Server Logged Sensitive Information
Spring Cloud Config Server Logged Sensitive Information
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.
GHSA
GHSA-j6hh-h3cf-c2hf: When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs
ghsa_unreviewed·2026-05-07
CVE-2026-41004 [MEDIUM] CWE-532 GHSA-j6hh-h3cf-c2hf: When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.
Red Hat
Spring Cloud Config Server: Spring Cloud Config: Spring Cloud Config Server: Information disclosure via trace logging
vendor_redhat·2026-05-07·CVSS 4.4
CVE-2026-41004 [MEDIUM] CWE-312 Spring Cloud Config Server: Spring Cloud Config: Spring Cloud Config Server: Information disclosure via trace logging
Spring Cloud Config Server: Spring Cloud Config: Spring Cloud Config Server: Information disclosure via trace logging
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusiv
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-41004 log4j: Spring Cloud Config Server: Information disclosure via trace logging [fedora-all]
bugzilla·2026-06-08·CVSS 4.4
CVE-2026-41004 [MEDIUM] CVE-2026-41004 log4j: Spring Cloud Config Server: Information disclosure via trace logging [fedora-all]
CVE-2026-41004 log4j: Spring Cloud Config Server: Information disclosure via trace logging [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-41004 Spring Cloud Config Server: Spring Cloud Config: Spring Cloud Config Server: Information disclosure via trace logging
bugzilla·2026-05-07·CVSS 4.4
CVE-2026-41004 [MEDIUM] CVE-2026-41004 Spring Cloud Config Server: Spring Cloud Config: Spring Cloud Config Server: Information disclosure via trace logging
CVE-2026-41004 Spring Cloud Config Server: Spring Cloud Config: Spring Cloud Config Server: Information disclosure via trace logging
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through
2026-05-07
Published