logo

High-Severity Spring Cloud Config Flaw Triggers File Leaks and SSRF

ID: f572745d-788c-5705-aef3-bfa41f56e95e

STIX ID: report--f572745d-788c-5705-aef3-bfa41f56e95e

Feed Name: securityonline.info

Threat Score
72/100

Date Published: 2026-03-24

Date Updated: 2026-04-23

Author: Ddos

...
...

A high-severity vulnerability (CVE-2026-22739, CVSS 8.6) in Spring Cloud Config lets attackers manipulate the profile parameter to perform directory traversal on native filesystem backends or SSRF when profiles are injected into repository URLs; multiple supported and unsupported versions are affected and vendors provide fixed releases (varying by support tier), with immediate upgrade to patched versions recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.