Spring Cloud Config 中关键功能缺失认证(Missing Authentication for Critical Function)漏洞:发往 Spring Cloud Config 服务器 端点的 Webhook 请求未进行校验。 该问题影响以下版本的 Spring Cloud Config: 5.0.0 至 5.0.4 4.3.0 至 4.3.4 4.0.0 至 4.2.8 3.1.14 及之前版本
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Cloud Config | 5.0.0≤ 5.0.4 |
affected |
4.3.0≤ 4.3.4 |
affected | ||
4.0.0≤ 4.2.8 |
affected | ||
≤ 3.1.14 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Spring | Spring Cloud Config | 5.0.0 ~ 5.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47841 | 7.4 HIGH | WebAuthn User Verification Bypass via Session Serialization |
| CVE-2026-47836 | 7.2 HIGH | Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN |
| CVE-2026-47842 | 6.5 MEDIUM | Deterministic AES/CBC Encryption in Spring Security AesBytesEncryptor Allows Ciphertext Co |
| CVE-2026-47848 | 6.1 MEDIUM | Reactor Netty WebSocket Client Leaks Credentials On Redirect |
| CVE-2026-47844 | 5.3 MEDIUM | Reactor Netty HTTP Server Leaks Exception Details |
| CVE-2026-47834 | 4.8 MEDIUM | Spring Data JPA Sort expression validation bypass |
| CVE-2026-47843 | 3.7 LOW | Reactor Netty may incorrectly route traffic due to DNS resolver reuse |
No comments yet