Spring Cloud Config
4 known vulnerabilities in Spring Cloud Config, 1 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-59315 CVSS 5.3 medium The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config 5.0.0 - 5.0.4…
- CVE-2026-47894 CVSS 7.5 high Spring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path…
- CVE-2026-47837 CVSS 9.8 critical Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config…
- CVE-2026-47836 CVSS 8.1 high The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is…