Spring Cloud Config
14 CVEs tracked. 1 of them are in CISA KEV.
This hub aggregates every CVE we track for Spring Cloud Config, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Spring Cloud Config CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 1 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 4 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 4 |
| 2026-09 | 0 |
Severity
How the 14 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical1
- High5
- Medium8
Latest CVEs
The 14 most recently published vulnerabilities affecting Spring Cloud Config.
- CVE-2026-59315Spring Cloud Config Monitor Denial of Service5.3
- CVE-2026-47894Spring Cloud Config Server Native Environment Repository Exposure4.9
- CVE-2026-47837Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests6.8
- CVE-2026-47836Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN7.2
- CVE-2026-40981When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects. Spring...7.5
- CVE-2026-41002The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Sprin...7.2
- CVE-2026-41004When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgr...4.4
- CVE-2026-40982Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially c...9.1
- CVE-2026-22739Spring Cloud Config Profile Substitution Can Allow Unintended Access To Files And Enable SSRF Attacks8.6
- CVE-2025-22232Spring Cloud Config Server May Not Use Vault Token Sent By Clients5.3
- CVE-2023-20859In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log file when it attem...5.5
- CVE-2020-5410Directory Traversal with spring-cloud-config-server7.5
- CVE-2020-5405Directory Traversal with spring-cloud-config-server6.5
- CVE-2019-3799Directory Traversal with spring-cloud-config-server6.5
Product grouping is registry-driven, with AI assist and human review. How it works