CVE-2026-47837

Updated on 26 Aug 2026

Severity

4.0 Medium severity

Details

CVSS score
4.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

Overview

About vulnerability

Webhook requests to Spring Cloud Config Server’s /monitor endpoint are not validated.

Details

Affected product:
Apache Log4j , Spring
Affected packages:
Spring Cloud @ 3.1.10 (+268 more)