Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.1
CVE-2026-40982: Spring Cloud Config Server may let attackers run code
CVE-2026-40982 · published 1 day ago
Summary
The Spring Cloud Config Server libraries from Spring Framework, VMware, and Root are affected by a security weakness that could let an attacker execute code on your system. This can expose sensitive configuration data or disrupt services. Upgrade to the latest patched versions released by the vendors as soon as possible.
What to do
- Update springframework org.springframework.cloud:spring-cloud-config-server to version 4.3.3.
- Update springframework org.springframework.cloud:spring-cloud-config-server to version 5.0.3.
- Update org.springframework.cloud:spring-cloud-config-server to version 4.3.0-aikido.2.
- Update io.root.org.springframework.cloud:spring-cloud-config-server to version 4.3.0-root.io.2.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| maven | springframework | org.springframework.cloud:spring-cloud-config-server |
>= 3.1.0, <= 3.1.13 >= 4.1.0, <= 4.1.9 >= 4.2.0, <= 4.2.6 >= 4.3.0, <= 4.3.2 >= 5.0.0, <= 5.0.2 Fix: upgrade to 4.3.3
|
| – | vmware | spring_cloud_config |
>= 3.1.0, < 3.1.14 >= 4.1.0, < 4.1.10 >= 4.2.0, < 4.2.7 >= 4.3.0, < 4.3.3 >= 5.0.0, < 5.0.3 cpe:2.3:a:vmware:spring_cloud_config:*:*:*:*:*:*:*:* |
| Root:Maven | – | org.springframework.cloud:spring-cloud-config-server |
< 4.3.0-aikido.2 Fix: upgrade to 4.3.0-aikido.2
|
| Root:Maven | – | io.root.org.springframework.cloud:spring-cloud-config-server |
< 4.3.0-root.io.2 Fix: upgrade to 4.3.0-root.io.2
|
Original advisory text
CVE-2026-40982 in org.springframework.cloud:spring-cloud-config-server - Patched by Root
Root has patched CVE-2026-40982 in the org.springframework.cloud:spring-cloud-config-server package for Root:Maven. Multiple fixed versions available.
References
- https://spring.io/security/cve-2026-40982 Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-40982
- https://github.com/advisories/GHSA-6g23-24mc-hx6x
- https://access.redhat.com/security/cve/CVE-2026-40982
- https://bugzilla.redhat.com/show_bug.cgi?id=2467619
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40982.json
Internet-facing
3 days
Internal
60 days
- Not known to be exploited
- Can be exploited automatically
- Gives an attacker full control
Type
CWE-22Path Traversal
Timeline
Published1 Oct 2026
Updated1 Oct 2026
First seen7 May 2026
Track software like this
Free during beta