Spring Cloud Config vulnerabilities
6 known vulnerabilities affecting spring/spring_cloud_config.
Total CVEs
6
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2019-3799P2MEDIUMCVSS 6.5PoC≥ 2.0, < v2.0.4.RELEASE≥ 1.4, < v1.4.6.RELEASE+1 more2019-05-06
CVE-2019-3799 [MEDIUM] CWE-22 CVE-2019-3799: Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.
Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arbitrary configuration files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead a dire
nvd
CVE-2026-40982P2CRITICALCVSS 9.1≥ 3.1.0, < 3.1.14≥ 4.1.0, < 4.1.10+3 more2026-05-07
CVE-2026-40982 [CRITICAL] CWE-22 CVE-2026-40982: Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or
nvd
CVE-2026-41002P3HIGHCVSS 8.1≥ 3.1.0, < 3.1.14≥ 4.1.0, < 4.1.10+3 more2026-05-07
CVE-2026-41002 [HIGH] CWE-367 CVE-2026-41002: The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server
The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: aff
nvd
CVE-2026-40981P3HIGHCVSS 7.5≥ 3.1.0, < 3.1.14≥ 4.1.0, < 4.1.10+3 more2026-05-07
CVE-2026-40981 [HIGH] CWE-639 CVE-2026-40981: When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affe
nvd
CVE-2025-22232P4MEDIUMCVSS 5.3≥ 4.2.x, < 4.2.2≥ 4.1.x, < 4.1.6+4 more2025-04-10
CVE-2025-22232 [MEDIUM] CWE-287 CVE-2025-22232: Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header whe
Spring Cloud Config Server may not use Vault token sent by clients using a X-CONFIG-TOKEN header when making requests to Vault.
Your application may be affected by this if the following are true:
* You have Spring Vault on the classpath of your Spring Cloud Config Server and
* You are using the X-CONFIG-TOKEN header to send a Vault token to the Spri
nvd
CVE-2026-41004P4MEDIUMCVSS 4.4≥ 3.1.0, < 3.1.14≥ 4.1.0, < 4.1.10+3 more2026-05-07
CVE-2026-41004 [MEDIUM] CWE-532 CVE-2026-41004: When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater
nvd