Description
The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads.
Spring Cloud Config 5.0.0 - 5.0.4
Spring Cloud Config 4.3.0 - 4.3.4
Spring Cloud Config 4.0.0 - 4.2.8
Spring Cloud Config 3.1.14 and earlier
Published: 2026-08-27
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Spring Cloud Config Monitor is vulnerable to denial‑of‑service attacks when it processes malicious payloads, which can cause the service to exhaust resources or crash, thereby disrupting configuration delivery; this flaw is a classic uncontrolled resource consumption weakness (CWE‑400) and has a CVSS score of 5.3 indicating moderate severity.

Affected Systems

Spring Cloud Config releases 3.1.14 and earlier, 4.0.0 to 4.2.8, 4.3.0 to 4.3.4, and 5.0.0 to 5.0.4 are affected.

Risk and Exploitability

The EPSS score is not available, making exploitation likelihood unclear, and the vulnerability is not listed in the CISA KEV catalog; the CVSS score of 5.3 indicates moderate severity. Attackers would typically locate the monitor endpoint through service discovery or probing, then send crafted payloads to exhaust memory or trigger a crash, highlighting the need for prompt patching or protective mitigations.

Generated by OpenCVE AI on August 28, 2026 at 07:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest Spring Cloud Config release that includes the CVE‑2026‑59315 fix (any version newer than 5.0.4, 4.3.4, 4.2.8, or 3.1.14).
  • Limit access to the configuration monitor endpoint to trusted networks or enforce authentication to block unauthenticated or malicious traffic.
  • Implement rate limiting or payload size restrictions on the monitor API to reduce the impact if a patch cannot be applied immediately.

Generated by OpenCVE AI on August 28, 2026 at 07:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 28 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400

Fri, 28 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring spring Cloud Config
Vendors & Products Spring
Spring spring Cloud Config

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier
Title Spring Cloud Config Monitor Denial of Service
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Spring Spring Cloud Config
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-08-27T18:04:42.065Z

Reserved: 2026-07-04T18:13:57.026Z

Link: CVE-2026-59315

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T20:17:57.547

Modified: 2026-08-27T20:17:57.547

Link: CVE-2026-59315

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T07:45:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption