CVE-2026-47837

Source
https://cve.org/CVERecord?id=CVE-2026-47837
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47837.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-47837
Published
2026-08-26T17:08:51Z
Modified
2026-09-06T03:46:00Z
Severity
  • 6.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H CVSS Calculator
Summary
Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Requests
Details

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated.

This issue affects Spring Cloud Config: from 5.0.0 through 5.0.4, from 4.3.0 through 4.3.4, from 4.0.0 through 4.2.8, and through 3.1.14.

Database specific
{
    "cna_assigner": "vmware",
    "cwe_ids": [
        "CWE-306"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/47xxx/CVE-2026-47837.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "5.0.0"
                },
                {
                    "last_affected": "5.0.4"
                },
                {
                    "introduced": "4.3.0"
                },
                {
                    "last_affected": "4.3.4"
                },
                {
                    "introduced": "4.0.0"
                },
                {
                    "last_affected": "4.2.8"
                },
                {
                    "last_affected": "3.1.14"
                }
            ],
            "source": "AFFECTED_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "5.0.0"
                },
                {
                    "last_affected": "5.0.4"
                },
                {
                    "introduced": "4.3.0"
                },
                {
                    "last_affected": "4.3.4"
                },
                {
                    "introduced": "4.0.0"
                },
                {
                    "last_affected": "4.2.8"
                },
                {
                    "last_affected": "3.1.14"
                }
            ],
            "source": "CPE_FIELD"
        },
        {
            "extracted_events": [
                {
                    "introduced": "5.0.0"
                },
                {
                    "fixed": "5.0.4"
                },
                {
                    "introduced": "4.3.0"
                },
                {
                    "fixed": "4.3.4"
                },
                {
                    "introduced": "4.0.0"
                },
                {
                    "fixed": "4.2.8"
                },
                {
                    "fixed": "3.1.14"
                }
            ],
            "source": "DESCRIPTION"
        }
    ]
}
References

Affected packages

Git / github.com/spring-cloud/spring-cloud-config

Affected ranges

Type
GIT
Repo
https://github.com/spring-cloud/spring-cloud-config
Events
Database specific
Show details
{
    "cpe": "cpe:2.3:a:vmware:spring_cloud_config:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "5.0.0"
        },
        {
            "fixed": "5.0.5"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

v5.*
v5.0.0
v5.0.1
v5.0.2
v5.0.3
v5.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-47837.json"