Spring Cloud Config Spring Cloud Config

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Spring Cloud Config.

By the Year

In 2026 there have been 1 vulnerability in Spring Cloud Config with an average score of 6.8 out of ten.

Year Vulnerabilities Average Score
2026 1 6.80

It may take a day or so for new Spring Cloud Config vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Spring Cloud Config Security Vulnerabilities

Spring Cloud Config /monitor Unauthenticated Webhook (V3.1.14-5.0.4)
CVE-2026-47837 6.8 - Medium - August 26, 2026

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from 4.0.0 through 4.2.8, and through 3.1.14.

Missing Authentication for Critical Function

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Spring Cloud Config or by Spring? Click the Watch button to subscribe.

Spring
Vendor

subscribe