CVE-2026-40982: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Spring Spring Cloud Config
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.
AI Analysis
Technical Summary
Spring Cloud Config server modules prior to versions 3.1.14, 4.1.10, 4.2.7, 4.3.3, and 5.0.3 allow an attacker to perform directory traversal via crafted URLs, leading to arbitrary file disclosure. This improper limitation of pathname to a restricted directory (CWE-22) can expose sensitive configuration or system files. The vulnerability is rated critical with a CVSS 3.1 base score of 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). Red Hat has published an advisory confirming the issue and the availability of fixed versions.
Potential Impact
Successful exploitation allows an unauthenticated remote attacker to read arbitrary files on the server hosting the Spring Cloud Config service. This can lead to disclosure of sensitive configuration data or other critical files, impacting confidentiality and integrity. There is no indication of availability impact. The vulnerability is critical due to the ease of exploitation and high confidentiality and integrity impact.
Mitigation Recommendations
Fixed versions are available and should be applied: upgrade to 3.1.14 or later for 3.1.x, 4.1.10 or later for 4.1.x, 4.2.7 or later for 4.2.x, 4.3.3 or later for 4.3.x, and 5.0.3 or later for 5.0.x. The Red Hat advisory confirms these fixed versions. No other mitigations or temporary workarounds are indicated. Users should prioritize upgrading to the fixed releases to remediate this vulnerability.
CVE-2026-40982: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Spring Spring Cloud Config
Description
Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request using a specially crafted URL that can lead to a directory traversal attack. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.
CVSS v3.1
Score 9.1critical
Affected software
pkg:maven/org.springframework.cloud/spring-cloud-configRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Spring Cloud Config server modules prior to versions 3.1.14, 4.1.10, 4.2.7, 4.3.3, and 5.0.3 allow an attacker to perform directory traversal via crafted URLs, leading to arbitrary file disclosure. This improper limitation of pathname to a restricted directory (CWE-22) can expose sensitive configuration or system files. The vulnerability is rated critical with a CVSS 3.1 base score of 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). Red Hat has published an advisory confirming the issue and the availability of fixed versions.
Potential Impact
Successful exploitation allows an unauthenticated remote attacker to read arbitrary files on the server hosting the Spring Cloud Config service. This can lead to disclosure of sensitive configuration data or other critical files, impacting confidentiality and integrity. There is no indication of availability impact. The vulnerability is critical due to the ease of exploitation and high confidentiality and integrity impact.
Mitigation Recommendations
Fixed versions are available and should be applied: upgrade to 3.1.14 or later for 3.1.x, 4.1.10 or later for 4.1.x, 4.2.7 or later for 4.2.x, 4.3.3 or later for 4.3.x, and 5.0.3 or later for 5.0.x. The Red Hat advisory confirms these fixed versions. No other mitigations or temporary workarounds are indicated. Users should prioritize upgrading to the fixed releases to remediate this vulnerability.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- vmware
- Date Reserved
- 2026-04-16T02:19:04.616Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-40982","vendor":"Red Hat"}]
Threat ID: 69fc1390cbff5d8610732602
Added to database: 05/07/2026, 04:22:40 UTC
Last enriched: 07/15/2026, 09:13:38 UTC
Last updated: 07/31/2026, 19:22:58 UTC
Views: 199
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.