GHSA-6g23-24mc-hx6x
Spring Cloud Config vulnerable to Path Traversal
CVEs:GHSA-6g23-24mc-hx6x
Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity).
The advisories below are ordered by the Vulnetix risk prioritization strategy: exploitation evidence first, scores second. On the interactive page you can switch to three other lenses.
Spring Cloud Config vulnerable to Path Traversal
CVEs:GHSA-6g23-24mc-hx6x
Spring Cloud Config vulnerable to Path Traversal
CVEs:CVE-2026-40982
Spring Cloud Config has an Authorization Bypass Through User-Controlled Key
CVEs:GHSA-2mh5-3cw6-hrrq
Spring Cloud Config has an Authorization Bypass Through User-Controlled Key
CVEs:CVE-2026-40981
Spring Cloud Config Server Susceptible To TOCTOU Attack
CVEs:GHSA-86wq-234q-r6wg
Spring Cloud Config Server Susceptible To TOCTOU Attack
CVEs:CVE-2026-41002
Spring Cloud Config Server Logged Sensitive Information
CVEs:GHSA-j6hh-h3cf-c2hf
Spring Cloud Config Server Logged Sensitive Information
CVEs:CVE-2026-41004
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs
CVEs:GHSA-v632-2m87-7469
Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs
CVEs:CVE-2026-41705
Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
CVEs:GHSA-q62f-h9x2-gcqc
Spring AI: ChatMemory DEFAULT_CONVERSATION_ID causes unintended cross-user data leakage
CVEs:CVE-2026-41712
Spring AI: Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor
CVEs:GHSA-5852-phmh-8fhr
Spring AI: Prompt Injection via Memory Poisoning in PromptChatMemoryAdvisor
CVEs:CVE-2026-41713
GHSA-rmvv-67vj-q642
CVEs:GHSA-rmvv-67vj-q642
CVEs:CVE-2026-22726
Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk
CVEs:GHSA-cc4m-mp48-x7qg
CVEs:CVE-2026-41863
GHSA-gq7j-4834-ccgp
CVEs:GHSA-gq7j-4834-ccgp
CVEs:CVE-2026-41009
GHSA-mhvf-vxjh-cwwp
CVEs:GHSA-mhvf-vxjh-cwwp
CVEs:CVE-2026-41704
Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.