GHSA-3qwq-q9vm-5j42

Suggest an improvement
Source
https://github.com/advisories/GHSA-3qwq-q9vm-5j42
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3qwq-q9vm-5j42/GHSA-3qwq-q9vm-5j42.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-3qwq-q9vm-5j42
Aliases
Published
2026-03-24T03:31:19Z
Modified
2026-03-26T17:26:30Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L CVSS Calculator
Summary
Spring Cloud Config Server: Path Traversal via Profile Parameter Allows Arbitrary File Access
Details

Vulnerability in Spring Cloud when substituting the profile parameter from a request made to the Spring Cloud Config Server configured to the native file system as a backend, because it was possible to access files outside of the configured search directories.This issue affects Spring Cloud: from 3.1.X before 3.1.13, from 4.1.X before 4.1.9, from 4.2.X before 4.2.3, from 4.3.X before 4.3.2, from 5.0.X before 5.0.2.

Database specific
{
    "cwe_ids":  [
        "CWE-22"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-03-26T17:08:55Z",
    "nvd_published_at":  "2026-03-24T01:17:00Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven
org.springframework.cloud:spring-cloud-config-server

Package

Name
org.springframework.cloud:spring-cloud-config-server
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.cloud/spring-cloud-config-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
4.3.2

Affected versions

4.*
4.3.0
4.3.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3qwq-q9vm-5j42/GHSA-3qwq-q9vm-5j42.json"
org.springframework.cloud:spring-cloud-config-server

Package

Name
org.springframework.cloud:spring-cloud-config-server
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.cloud/spring-cloud-config-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.0.0-M1
Fixed
5.0.2

Affected versions

5.*
5.0.0-M1
5.0.0-M2
5.0.0-M3
5.0.0-M4
5.0.0-RC1
5.0.0
5.0.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3qwq-q9vm-5j42/GHSA-3qwq-q9vm-5j42.json"
org.springframework.cloud:spring-cloud-config-server

Package

Name
org.springframework.cloud:spring-cloud-config-server
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.cloud/spring-cloud-config-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.2.0
Last Affected
4.2.4

Affected versions

4.*
4.2.0
4.2.1
4.2.2
4.2.3
4.2.4

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3qwq-q9vm-5j42/GHSA-3qwq-q9vm-5j42.json"
org.springframework.cloud:spring-cloud-config-server

Package

Name
org.springframework.cloud:spring-cloud-config-server
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.cloud/spring-cloud-config-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.0.0
Last Affected
4.1.7

Affected versions

4.*
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3qwq-q9vm-5j42/GHSA-3qwq-q9vm-5j42.json"
org.springframework.cloud:spring-cloud-config-server

Package

Name
org.springframework.cloud:spring-cloud-config-server
View open source insights on deps.dev
Purl
pkg:maven/org.springframework.cloud/spring-cloud-config-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.1.10

Affected versions

1.*
1.0.0.RELEASE
1.0.1.RELEASE
1.0.2.RELEASE
1.0.3.RELEASE
1.0.4.RELEASE
1.1.0.RELEASE
1.1.1.RELEASE
1.1.2.RELEASE
1.1.3.RELEASE
1.2.0.M1
1.2.0.RELEASE
1.2.1.RELEASE
1.2.2.RELEASE
1.2.3.RELEASE
1.3.0.RELEASE
1.3.1.RELEASE
1.3.2.RELEASE
1.3.3.RELEASE
1.3.4.RELEASE
1.4.0.RELEASE
1.4.1.RELEASE
1.4.2.RELEASE
1.4.3.RELEASE
1.4.4.RELEASE
1.4.5.RELEASE
1.4.6.RELEASE
1.4.7.RELEASE
2.*
2.0.0.RELEASE
2.0.1.RELEASE
2.0.2.RELEASE
2.0.3.RELEASE
2.0.4.RELEASE
2.0.5.RELEASE
2.1.0.RELEASE
2.1.1.RELEASE
2.1.2.RELEASE
2.1.3.RELEASE
2.1.4.RELEASE
2.1.5.RELEASE
2.1.6.RELEASE
2.1.7.RELEASE
2.1.8.RELEASE
2.1.9.RELEASE
2.2.0.RELEASE
2.2.1.RELEASE
2.2.2.RELEASE
2.2.3.RELEASE
2.2.4.RELEASE
2.2.5.RELEASE
2.2.6.RELEASE
2.2.7.RELEASE
2.2.8.RELEASE
3.*
3.0.0
3.0.1
3.0.2
3.0.3
3.0.4
3.0.5
3.0.6
3.0.7
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.1.5
3.1.6
3.1.7
3.1.8
3.1.9
3.1.10

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-3qwq-q9vm-5j42/GHSA-3qwq-q9vm-5j42.json"