CVE-2026-40982
Spring Spring Cloud Config, Red Hat Enterprise Linux 8, Red Hat JBoss Enterprise Application Platform Expansion Pack
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade...
- CVSS
- 9.1
- EPSS
- 0.73% 50.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.07