CVE-2026-22739
EUVD-2026-1466424.03.2026, 01:17
Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13, from 4.1.X before 4.1.9, from 4.2.X before 4.2.3, from 4.3.X before 4.3.2, from 5.0.X before 5.0.2.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| vmware | spring_cloud_config | 𝑥 < 3.1.13 |
| vmware | spring_cloud_config | 4.1.0 ≤ 𝑥 < 4.1.9 |
| vmware | spring_cloud_config | 4.2.0 ≤ 𝑥 < 4.2.6 |
| vmware | spring_cloud_config | 4.3.0 ≤ 𝑥 < 4.3.2 |
| vmware | spring_cloud_config | 5.0.0 ≤ 𝑥 < 5.0.2 |
𝑥
= Vulnerable software versions