Inclusion of Sensitive Information in Log Files in Spring Cloud Config - CVE-2026-41004
Published: May 7, 2026
Spring Cloud Config
Detailed vulnerability description
The vulnerability allows a local privileged user to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into log files in Spring Cloud Config Server when trace logging is enabled. A local privileged user can read plain-text log entries to disclose sensitive information.
Only instances with trace logging enabled are vulnerable.