CVE-2026-40982 | Spring Cloud Config up to 5.0.2 URL path traversal
A vulnerability labeled as critical has been found in Spring Cloud Config up to 3.1.13/4.1.9/4.2.6/4.3.2/5.0.2. This affects an unknown part of the component URL Handler. The manipulation results in path traversal.
This vulnerability is known as CVE-2026-40982. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.