CVE-2026-47836

Source
https://cve.org/CVERecord?id=CVE-2026-47836
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47836.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-47836
Published
2026-08-26T17:05:21Z
Modified
2026-09-06T03:46:20Z
Severity
  • 7.2 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN
Details

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier

Database specific
{
    "cna_assigner": "vmware",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47836.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "5.0.0"
                },
                {
                    "last_affected": "5.0.4"
                },
                {
                    "introduced": "4.3.0"
                },
                {
                    "last_affected": "4.3.4"
                },
                {
                    "introduced": "4.0.0"
                },
                {
                    "last_affected": "4.2.8"
                },
                {
                    "last_affected": "3.1.14"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/spring-cloud/spring-cloud-config

Affected ranges

Type
GIT
Repo
https://github.com/spring-cloud/spring-cloud-config
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:vmware:spring_cloud_config:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.0.5"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v5.*
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47836.json"