CVE-2026-47836
published 2026-08-26CVE-2026-47836: The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to…
PriorityP335high7.2CVSS 3.1
AVLACHPRHUINSCCHIHAN
EPSS
0.08%
0.2th percentile
The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks.
Spring Cloud Config 5.0.0 - 5.0.4
Spring Cloud Config 4.3.0 - 4.3.4
Spring Cloud Config 4.0.0 - 4.2.8
Spring Cloud Config 3.1.14 and earlier
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_cloud_config | <= 3.1.14 | — |
| spring | spring_cloud_config | 4.0.0 – 4.2.8 | — |
| spring | spring_cloud_config | 4.3.0 – 4.3.4 | — |
| spring | spring_cloud_config | 5.0.0 – 5.0.4 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
2026-08-26
Published