All 8 CVE vulnerabilities found in Spring Cloud Config, with AI-generated Chinese analysis, references, and POCs.
Vendor: Spring
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-40981 | Spring Cloud Config 远程代码执行漏洞 CWE-639 | 7.5 | High | 2026-05-07 |
| CVE-2026-41002 | Spring Cloud Config 多个版本存在TOCTOU漏洞 CWE-367 | 7.4 | High | 2026-05-07 |
| CVE-2026-41004 | Spring Cloud Config多版本敏感信息明文日志泄露 CWE-532 | 4.4 | Medium | 2026-05-07 |
| CVE-2026-40982 | Spring Cloud Config目录遍历漏洞 CWE-22 | 9.1 | Critical | 2026-05-07 |
| CVE-2025-22232 | Spring Cloud Config Server May Not Use Vault Token Sent By Clients CWE-287 | 5.3 | Medium | 2025-04-10 |
| CVE-2020-5410 | Directory Traversal with spring-cloud-config-server CWE-23 | 6.5 | - | 2020-06-02 |
| CVE-2020-5405 | Directory Traversal with spring-cloud-config-server CWE-23 | 6.5 | - | 2020-03-05 |
| CVE-2019-3799 | Directory Traversal with spring-cloud-config-server CWE-22 | 6.5 | - | 2019-05-06 |
All 8 known CVE vulnerabilities affecting Spring Cloud Config with full Chinese analysis, references, and POCs where available.