Known vulnerabilities in Spring Cloud Config 4.1.6

Vendor: Broadcom
Version: 4.1.6
Software CPE: cpe:2.3:a:broadcom:spring_cloud_config:*:*:*:*:*:*:*:*
Total vulnerabilities: 5
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Spring Cloud Config version 4.1.6 Spring Cloud Config 4.1.6 is affected by 5 vulnerabilities: 2 high, 1 medium, 2 low Critical High Medium Low

Vulnerabilities (5)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU130473 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-40982
CWE-22 High
No
No
3.1.14, 4.1.10, 4.2.7, 4.3.3, 5.0.3 07.05.2026 SB2026050793
#VU130472 - Improper Access Control
CVE-2026-40981
CWE-284 Medium
No
No
3.1.14, 4.1.10, 4.2.7, 4.3.3, 5.0.3 07.05.2026 SB2026050793
#VU130471 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVE-2026-41002
CWE-367 Low
No
No
3.1.14, 4.1.10, 4.2.7, 4.3.3, 5.0.3 07.05.2026 SB2026050793
#VU130470 - Information Exposure Through Log Files
CVE-2026-41004
CWE-532 Low
No
No
3.1.14, 4.1.10, 4.2.7, 4.3.3, 5.0.3 07.05.2026 SB2026050793
#VU128384 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-22739
CWE-22 High
No
No
3.1.13, 4.1.9, 4.2.6, 4.3.2, 5.0.2 28.04.2026 SB20260428209