Spring Cloud Config
Vendor:
First CVE: May 6, 2019 · Active for 7 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
12.5%
KEV Rate
Higher KEV Rate than 97% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Spring Cloud Config over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 6, 2019
7 years ago
Most Recent CVE
May 7, 2026
78 days ago
CVE Severity & Scoring
Spring Cloud Config8 CVEs
50%
38%
13%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (25.0%)
Network6 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None6 (75.0%)
Unknown0 (0.0%)
Required2 (25.0%)
Privileges Required
Low1 (12.5%)
High1 (12.5%)
None6 (75.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-5410HIGH Spring Cloud Config, versions 2.2.x prior to 2.2.3, versions 2.1.x prior to 2.1.9, and older unsupported versions allow applications to serve arbitrary configuration files through | Jun 2, 2020 | 7.5 | 97 | YES | YES |
CVE-2019-3799MEDIUM Spring Cloud Config, versions 2.1.x prior to 2.1.2, versions 2.0.x prior to 2.0.4, and versions 1.4.x prior to 1.4.6, and older unsupported versions allow applications to serve arb | May 6, 2019 | 6.5 | 88 | NO | YES |
CVE-2020-5405MEDIUM Spring Cloud Config, versions 2.2.x prior to 2.2.2, versions 2.1.x prior to 2.1.7, and older unsupported versions allow applications to serve arbitrary configuration files through | Mar 5, 2020 | 6.5 | 71 | NO | YES |
CVE-2026-40982CRITICAL Spring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or attacker, can send a request us | May 7, 2026 | 9.1 | 39 | NO | NO |
CVE-2026-40981HIGH When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP | May 7, 2026 | 7.5 | 33 | NO | NO |
CVE-2026-41002HIGH The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTO | May 7, 2026 | 8.1 | 31 | NO | NO |
CVE-2026-41004MEDIUM When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 | May 7, 2026 | 4.4 | 21 | NO | NO |
CVE-2023-20859MEDIUM In Spring Vault, versions 3.0.x prior to 3.0.2 and versions 2.3.x prior to 2.3.3 and older versions, an application is vulnerable to insertion of sensitive information into a log f | Mar 23, 2023 | 5.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
1 CVE
12.5% of CVEs· 97th percentile
Metasploit
2 CVEs
25.0% of CVEs· 98th percentile
Nuclei
3 CVEs
37.5% of CVEs· 98th percentile
ExploitDB
1 CVE
12.5% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Spring Cloud Config
Top CWEs
Versions
No cataloged versions.