🔥 热门漏洞情报 · NVD-Latest · 2026-05-07
CVE-2026-40982 (CVSS 9.1) - Spring Cloud Config allows applications to serve arbitrary text and binary files
Critical · CVSS 9.1
路径遍历
CVE-2026-40982
📋 漏洞概述
Spring Cloud Config目录遍历漏洞,攻击者可请求特制URL读取服务器任意文件。
📋 基础信息
受影响版本Spring Cloud Config 3.1.0-3.1.13, 4.1.0-4.1.9, 4.2.0-4.2.6,