← Vulnerability feed

Vulnerability record · CVE-2026-41002 · published 7 May 2026

CVE-2026-41002: Vmware spring cloud config toctou race condition vulnerability

Vmware · Spring Cloud Config

The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

8.1 CVSS 3.1 High EPSS 0.22% · top 89.2% CWE-367 · TOCTOU race condition
8.1CVSS 3.1 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

The base directory (`spring.cloud.config.server.git.basedir`) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-41002 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2020-5410Spring Cloud Config Server path traversal exposes arbitrary filesSpring Cloud Config Server versions 2.2.x before 2.2.3, 2.1.x before 2.1.9, and older unsupported releases serve arbitrary configuration files via th…KEVEPSS 96%analysed9.8CVE-2026-47837Vmware spring cloud config missing authentication for critical function vulnerabilityMissing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /mon…EPSS 0.55%9.1CVE-2026-40982Vmware spring cloud config path traversal vulnerabilitySpring Cloud Config allows applications to serve arbitrary text and binary files through the spring-cloud-config-server module. A malicious user, or …EPSS 0.82%8.6CVE-2026-22739Vmware spring cloud config path traversal vulnerabilityVulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native …EPSS 1.2%8.1CVE-2026-47836Vmware spring cloud config toctou race condition vulnerabilityThe base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to tim…EPSS 0.22%7.5CVE-2026-47894Vmware spring cloud config vulnerabilitySpring Cloud Config Server native environment repository allows exposure of configuration files outside of the configured repository path. Spring Clo…EPSS 0.49%7.5CVE-2026-40981Vmware spring cloud config insecure direct object reference vulnerabilityWhen using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially expos…EPSS 0.48%6.5CVE-2020-5405Spring Cloud Config Server path traversal in config file servingSpring Cloud Config Server versions 2.2.x before 2.2.2, 2.1.x before 2.1.7, and older unsupported releases can be made to serve arbitrary configurati…EPSS 69%analysed

Source: NIST National Vulnerability Database (record CVE-2026-41002), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.