CVE-2026-59315: Spring Cloud Config Monitor Denial of Service
Published Aug 27, 2026
·Updated
The Spring Cloud Config Monitor is susceptible to Denial of Service attacks via malicious payloads. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier
Affected Software
5 affected components
Spring Spring Cloud Config Monitor>=5.0.0<=5.0.4, >=4.3.0<=4.3.4, >=4.0.0<=4.2.8, <=3.1.14
VMware Spring Cloud Config<3.1.15
VMware Spring Cloud Config>=4.0.0<4.2.9
VMware Spring Cloud Config>=4.3.0<4.3.5
VMware Spring Cloud Config>=5.0.0<5.0.5
Event History
Aug 27, 2026
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which deployments are exposed to this issue?
Deployments using Spring Cloud Config Monitor in Spring Cloud Config 5.0.0 through 5.0.4, 4.3.0 through 4.3.4, 4.0.0 through 4.2.8, or 3.1.14 and earlier are affected.
2
Does exploitation require authentication or user interaction?
No. The listed CVSS vector indicates the issue is network-reachable, requires no privileges, and requires no user interaction.
3
What is the expected impact of a successful attack?
The stated impact is denial of service. The CVSS vector indicates availability impact only, with no confidentiality or integrity impact.