CVE-2026-22739HIGH 8.6EPSS p64.7%
CVE-2026-22739CVE-2026-22739
Description
Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13, from 4.1.X before 4.1.9, from 4.2.X before 4.2.3, from 4.3.X before 4.3.2, from 5.0.X before 5.0.2.
Scoring
| CVSS 3.1 | 8.6 (HIGH) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L |
| EPSS | 1.22% probability of exploitation · percentile 64.7% · 2026-06-18T12:00:27Z |
| Published | 2026-03-24 |
| Last modified | 2026-03-24 |
Underlying weaknesses· 1
References
1
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')cwe-22 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.