Intel

AIKIDO-2026-918519

spring-cloud-config-monitor is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)CVE-2026-59315 Published 5 days ago

53

Medium Risk

This Affects:

JAVAspring-cloud-config-monitor
0.0.1 - 5.0.4
Fixed in 5.0.5
Are you affected? Scan for Free

TL;DR

spring-cloud-config-monitor can be exhausted by malicious webhook payloads. A remote sender can degrade or stop configuration-change notifications. Other clients then miss refreshes. The patch rejects oversized or malformed monitor payloads.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and the Config Monitor endpoint is exposed.

Background info

spring-cloud-config-monitor is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 5.0.4.

How to fix this

Upgrade the org.springframework.cloud:spring-cloud-config-monitor library to the patch version.