High-Severity Spring Cloud Config Flaw Triggers File Leaks and SSRF
ID: f572745d-788c-5705-aef3-bfa41f56e95e
STIX ID: report--f572745d-788c-5705-aef3-bfa41f56e95e
Feed Name: securityonline.info
Threat Score
A high-severity vulnerability (CVE-2026-22739, CVSS 8.6) in Spring Cloud Config lets attackers manipulate the profile parameter to perform directory traversal on native filesystem backends or SSRF when profiles are injected into repository URLs; multiple supported and unsupported versions are affected and vendors provide fixed releases (varying by support tier), with immediate upgrade to patched versions recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
