Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1167 articles · 105240 vulns · 38/41 feeds (7d)
← Back to list
8.6
CVE-2026-22739EXPLOITED
Spring · Spring Cloud Config

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible t

Description

A vulnerability has been discovered in Spring Cloud Config that allows an attacker to perform server-side request forgery (SSRF).

Affected Products

VendorProductVersions
SpringSpring Cloud Config3.1.3, 4.2.6, 4.3.2, 3.1.13, 4.1.9, 5.0.2

References

  • https://spring.io/security/cve-2026-22739

Related News (2 articles)

Tier B
CCCS Canada15h ago
Spring security advisory (AV26-288)
→ No new info (linked only)
Tier B
CERT-FR3d ago
Vulnérabilité dans Spring Cloud Config (24 mars 2026)
→ No new info (linked only)
CVSS 3.18.6 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-22, CWE-20, CWE-200
Published3/24/2026
Last enriched4h agov7
Tags
Spring Security AdvisoryCVE-2026-22739
Trending Score54
Source articles2
Independent2
Info Completeness10/14
Missing: epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Version History

v7
Last enriched 4h ago
v7Tier B4h ago

Updated affected versions and added new CWE and CVE information.

cweIdstags
via CCCS Canada
v6Tier B4h ago

Updated affected versions, added new CWE, and included new tags related to Spring Security Advisory.

cweIdstags
via CCCS Canada
v5Tier B4h ago

Updated affected versions to include 3.1.13, 4.1.9, and confirmed patch available is 5.0.2.

affectedVersions
via CERT-FR
v4Tier B11h ago

Updated description with new technical details and added affected version 4.2.6.

description
via CERT-FR
v3Tier B11h ago

Updated affected versions to include 4.3.2 and marked exploit availability and active exploitation as true.

affectedVersionsexploitAvailableactivelyExploited
via CCCS Canada
v2Tier B12h ago

Updated vendor to Spring, product to Spring Cloud Config, added affected versions 3.1.3 and 4.2.6, and marked exploit availability and active exploitation as true.

vendorproductaffectedVersionspatchAvailable
via CCCS Canada
v112h ago

Initial creation