Known vulnerabilities in Spring Cloud Config 3.1.9
Vendor:
Broadcom
Software:
Spring Cloud Config
Version:
3.1.9
Software CPE:
cpe:2.3:a:broadcom:spring_cloud_config:*:*:*:*:*:*:*:*
Website:
https://www.broadcom.com/
Total vulnerabilities:
6
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
9.3
Vulnerabilities by Severity
5.0.5
5.0.4
4.3.4
3.1.14
4.1.10
4.2.7
5.0.3
4.3.3
4.2.6
4.2.5
4.1.9
4.1.8
3.1.13
3.1.12
3.1.11
5.0.2
4.3.2
5.0.1
4.3.1
4.2.4
5.0.0
4.2.3
4.1.7
4.3.0
4.0.10
4.0.9
4.0.8
4.0.7
4.0.6
4.2.2
4.1.6
3.1.10
4.2.1
4.1.5
4.2.0
4.1.4
4.1.3
4.1.2
4.1.1
4.0.5
3.1.9
4.1.0
4.0.4
3.1.8
4.0.3
3.1.7
4.0.2
3.1.6
4.0.1
4.0.0
3.1.5
3.1.4
3.0.7
3.1.3
3.1.2
3.1.1
3.0.6
3.1.0
3.0.5
3.0.4
2.2.8
3.0.3
2.2.7
3.0.2
3.0.1
3.0.0
2.2.6
2.2.5
2.2.4
2.2.3
2.1.9
2.1.8
2.2.2
2.1.7
2.1.6
2.2.1
2.1.5
2.1.4
2.1.3
2.0.5
1.4.7
2.2.0.
2.2.0.RC2
2.2.0.RC1
2.2.0.M3
2.2.0.M2
2.2.0.M1
v2.1.2.
v2.1.1.
v2.1.0.RC3
v2.1.0.RC2
v2.1.0.RC1
v2.1.0.M3
v2.1.0.M2
v2.1.0.M1
v2.1.0.
v2.0.4.
v2.0.3.
v2.0.2.
v2.0.1.
v2.0.0.RC2
v2.0.0.RC1
v2.0.0.M9
v2.0.0.M8
v2.0.0.M7
v2.0.0.M6
v2.0.0.M5
v2.0.0.M4
v2.0.0.M3
v2.0.0.M2
v2.0.0.M1
v2.0.0.
v1.4.6.
v1.4.5.
v1.4.4.
v1.4.3.
v1.4.2.
v1.4.1.
v1.4.0.RC1
v1.4.0.M1
v1.4.0.
v1.3.4.
v1.3.3.
v1.3.2.
v1.3.1.
v1.3.0.RC1
v1.3.0.M2
v1.3.0.M1
v1.3.0.
v1.2.3.
v1.2.2.
v1.2.1.
v1.2.0.RC1
v1.2.0.M1
v1.2.0.
v1.1.3.
v1.1.2.
v1.1.1.
v1.1.0.RC2
v1.1.0.RC1
v1.1.0.M5
v1.1.0.M4
v1.1.0.M3
v1.1.0.M2
v1.1.0.M1
1.1.0.
1.0.4.
1.0.3.
1.0.1.
1.0.0.RC3
1.0.0.RC2
1.0.0.RC1
1.0.0.M4
1.0.0.M3
1.0.0.
1.0.0.M1
Vulnerabilities (6)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU130473 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-40982 |
CWE-22 | High | 3.1.14, 4.1.10, 4.2.7, 4.3.3, 5.0.3 | 07.05.2026 |
SB2026050793 |
||
| #VU130472 - Improper Access Control CVE-2026-40981 |
CWE-284 | Medium | 3.1.14, 4.1.10, 4.2.7, 4.3.3, 5.0.3 | 07.05.2026 |
SB2026050793 |
||
| #VU130471 - Time-of-check Time-of-use (TOCTOU) Race Condition CVE-2026-41002 |
CWE-367 | Low | 3.1.14, 4.1.10, 4.2.7, 4.3.3, 5.0.3 | 07.05.2026 |
SB2026050793 |
||
| #VU130470 - Information Exposure Through Log Files CVE-2026-41004 |
CWE-532 | Low | 3.1.14, 4.1.10, 4.2.7, 4.3.3, 5.0.3 | 07.05.2026 |
SB2026050793 |
||
| #VU128384 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CVE-2026-22739 |
CWE-22 | High | 3.1.13, 4.1.9, 4.2.6, 4.3.2, 5.0.2 | 28.04.2026 |
SB20260428209 |
||
| #VU107154 - Improper Authorization CVE-2025-22232 |
CWE-285 | Medium | 3.1.10, 4.0.10, 4.1.6, 4.2.1 | 08.04.2025 |
SB2025040845 |