Impact
The Spring Cloud Config Monitor is vulnerable to denial‑of‑service attacks when it processes malicious payloads, which can cause the service to exhaust resources or crash, thereby disrupting configuration delivery; this flaw is a classic uncontrolled resource consumption weakness (CWE‑400) and has a CVSS score of 5.3 indicating moderate severity.
Affected Systems
Spring Cloud Config releases 3.1.14 and earlier, 4.0.0 to 4.2.8, 4.3.0 to 4.3.4, and 5.0.0 to 5.0.4 are affected.
Risk and Exploitability
The EPSS score is not available, making exploitation likelihood unclear, and the vulnerability is not listed in the CISA KEV catalog; the CVSS score of 5.3 indicates moderate severity. Attackers would typically locate the monitor endpoint through service discovery or probing, then send crafted payloads to exhaust memory or trigger a crash, highlighting the need for prompt patching or protective mitigations.
OpenCVE Enrichment