Critical Spring Vulnerabilities Expose Arbitrary Files and GCP Secrets
ID: bfae52ec-d4cf-58d3-982e-6a04e5b6e0a4
STIX ID: report--bfae52ec-d4cf-58d3-982e-6a04e5b6e0a4
Feed Name: cybersecurityNews.com
This advisory describes four vulnerabilities in Spring Cloud Config—most notably a critical directory traversal (CVE-2026-40982) that permits arbitrary file access, high-severity flaws that can expose Google Cloud secrets and enable a time-of-check-time-of-use race during Git cloning, and a medium-severity issue where trace logging can write sensitive data to logs. Multiple supported release lines are affected; the Spring team has published patched versions and a configuration workaround for the GCP secrets issue, and administrators are urged to upgrade immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
