logo

Critical Spring Cloud Config Flaws Expose Arbitrary Files and GCP Secrets

ID: d907c828-26df-574a-8c9c-471414b5e712

STIX ID: report--d907c828-26df-574a-8c9c-471414b5e712

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-05-07

Date Updated: 2026-05-07

Author: Ddos

...
...

The Spring Cloud Config project issued security updates addressing four vulnerabilities across multiple release lines: a Critical directory traversal (CVE-2026-40982, CVSS 9.1) allowing arbitrary filesystem reads, a High-severity GCP secret exposure across projects (CVE-2026-40981), a TOCTOU weakness in Git repository handling (CVE-2026-41002), and plaintext sensitive data exposure in trace logs (CVE-2026-41004). Users are advised to upgrade to the fixed OSS versions (4.3.3, 5.0.3) to mitigate these risks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.