Critical Spring Cloud Config Flaws Expose Arbitrary Files and GCP Secrets
ID: d907c828-26df-574a-8c9c-471414b5e712
STIX ID: report--d907c828-26df-574a-8c9c-471414b5e712
Feed Name: securityonline.info
The Spring Cloud Config project issued security updates addressing four vulnerabilities across multiple release lines: a Critical directory traversal (CVE-2026-40982, CVSS 9.1) allowing arbitrary filesystem reads, a High-severity GCP secret exposure across projects (CVE-2026-40981), a TOCTOU weakness in Git repository handling (CVE-2026-41002), and plaintext sensitive data exposure in trace logs (CVE-2026-41004). Users are advised to upgrade to the fixed OSS versions (4.3.3, 5.0.3) to mitigate these risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
