CVE-2026-59315: Spring Cloud Config Monitor Denial of Service
Published Aug 27, 2026
·Updated
The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier
Affected Software
1 affected component
Spring Spring Cloud Config Monitor>=5.0.0<=5.0.4, >=4.3.0<=4.3.4, >=4.0.0<=4.2.8, <=3.1.14
Event History
Aug 27, 2026
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverity
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Deployments using Spring Cloud Config Monitor in Spring Cloud Config 5.0.0 through 5.0.4, 4.3.0 through 4.3.4, 4.0.0 through 4.2.8, or 3.1.14 and earlier are affected.
2
Does exploitation require authentication or user interaction?
No. The listed CVSS vector indicates the issue is network-reachable, requires no privileges, and requires no user interaction.
3
What is the expected impact of a successful attack?
The stated impact is denial of service. The CVSS vector indicates availability impact only, with no confidentiality or integrity impact.