CVE-2026-47836

Updated on 26 Aug 2026

Severity

7.0 High severity

Details

CVSS score
7.0
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:N

Overview

About vulnerability

The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks.

Details

Affected product:
Apache Log4j , Spring
Affected packages:
log4j-api @ 2.13.3 (+268 more)