CVE-2026-41004: VMware Spring Cloud Config

Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.

When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

Affected products

  • VMware Spring Cloud Config: from 3.1.0, before 3.1.14 (fixed in 3.1.14); from 4.1.0, before 4.1.10 (fixed in 4.1.10); from 4.2.0, before 4.2.7 (fixed in 4.2.7); from 4.3.0, before 4.3.3 (fixed in 4.3.3); from 5.0.0, before 5.0.3 (fixed in 5.0.3)

Published 2026-05-07. Last modified 2026-06-17.