Intel

AIKIDO-2026-10770

spring-cloud-config-server is vulnerable to Race Condition (TOCTOU)

Race Condition (TOCTOU)CVE-2026-41002 Published May 8, 2026

72

High Risk

This Affects:

javaspring-cloud-config-server
0.0.1 - 3.1.13
Fixed in 3.1.14
4.0.0 - 4.1.9
Fixed in 4.1.10
4.2.0 - 4.2.6
Fixed in 4.2.7
4.3.0 - 4.3.2
Fixed in 4.3.3
5.0.0 - 5.0.2
Fixed in 5.0.3
Are you affected? Scan for Free

TL;DR

The base directory (spring.cloud.config.server.git.basedir) used by the Spring Cloud Config Server to clone Git repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

spring-cloud-config-server is vulnerable to Race Condition (TOCTOU) in versions 0.0.1 - 3.1.13, 4.0.0 - 4.1.9, 4.2.0 - 4.2.6, 4.3.0 - 4.3.2 and 5.0.0 - 5.0.2.

How to fix this

Upgrade the org.springframework.cloud:spring-cloud-config-server library to a patch version.