CVE-2026-41004Disclosure(vmware / spring_cloud_config)

LOWCVSS 4.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrade to 3.1.14 or greater (Enterprise Support Only). Spring Cloud Config 4.1.x: affected from 4.1.0 through 4.1.9 (inclusive); upgrade to 4.1.10 or greater (Enterprise Support Only). Spring Cloud Config 4.2.x: affected from 4.2.0 through 4.2.6 (inclusive); upgrade to 4.2.7 or greater (Enterprise Support Only). Spring Cloud Config 4.3.x: affected from 4.3.0 through 4.3.2 (inclusive); upgrade to 4.3.3 or greater. Spring Cloud Config 5.0.x: affected from 5.0.0 through 5.0.2 (inclusive); upgrade to 5.0.3 or greater.

0.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-532

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • spring_cloud_config

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
spring_cloud_config

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-05-07: 3Technical Details · 2026-05-07: 105-07
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-41004 📊 Severity: 4.4 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-41004 #CVE-2026-41004 #CVE #Medium #CyberSecurity #InfoSec https://t.co/kYagUEUeNq

    Post summary

    The tweet simply announces CVE-2026-41004 with basic metadata and an NVD link, lacking any technical, exploit, or mitigation details.

    0001044
    152 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-41004 When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs. Spring Cloud Config 3.1.x: affected from 3.1.0 t… https://www.cve.org/CVERecord?id=CVE-2026-41004

    Post summary

    The CVE-2026-41004 disclosure notes that trace logging in Spring Cloud Config Server 3.1.x can expose sensitive data in plain text logs, but does not provide PoC, exploit, or patch details.

    0000097
    57.4K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41004 Sensitive Information Disclosure in Spring Cloud Config Server Trace Logging https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41004

    Post summary

    The post merely announces CVE‑2026‑41004 as a sensitive information disclosure issue in Spring Cloud Config Server trace logging, with no further details or actionable information.

    0000044
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appvmwarespring_cloud_config---

Explore more