{"api_version":"v1","generated_at":"2026-10-07T10:10:00+00:00","product":{"cve_count":10,"evidence_gap_note":"This CVE identity is linked to an existing Lifecycle product history.","id":"security:cve-spring-spring-cloud-config-3c85c5a334b7","lifecycle_state":"covered","linked_lifecycle_url":"https://lifecycle.blacktree.nl/targets/spring-cloud","name":"Spring Cloud Config","next_cursor":null,"observations":[{"affected":"5.0.0 \u2264 5.0.4; 4.3.0 \u2264 4.3.4; 4.0.0 \u2264 4.2.8; \u2264 3.1.14","affected_versions_present":true,"cve_id":"CVE-2026-59315","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-59315","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-28T22:47:23.491Z","patch_url":"","primary_source":"","published":"2026-08-27T18:04:42.065Z"},{"affected":"5.0.0 \u2264 5.0.4; 4.3.0 \u2264 4.3.4; 4.0.0 \u2264 4.2.8; \u2264 3.1.14","affected_versions_present":true,"cve_id":"CVE-2026-47894","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47894","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-27T14:18:07.039Z","patch_url":"","primary_source":"","published":"2026-08-27T05:20:32.282Z"},{"affected":"5.0.0 \u2264 5.0.4; 4.3.0 \u2264 4.3.4; 4.0.0 \u2264 4.2.8; \u2264 3.1.14","affected_versions_present":true,"cve_id":"CVE-2026-47837","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47837","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-26T18:50:49.428Z","patch_url":"","primary_source":"","published":"2026-08-26T17:08:51.832Z"},{"affected":"5.0.0 \u2264 5.0.4; 4.3.0 \u2264 4.3.4; 4.0.0 \u2264 4.2.8; \u2264 3.1.14","affected_versions_present":true,"cve_id":"CVE-2026-47836","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-47836","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-08-27T03:58:24.390Z","patch_url":"","primary_source":"","published":"2026-08-26T17:05:21.979Z"},{"affected":"3.1.0 < 3.1.14; 4.1.0 < 4.1.10; 4.2.0 < 4.2.7; 4.3.0 < 4.3.3; 5.0.0 < 5.0.3","affected_versions_present":true,"cve_id":"CVE-2026-40981","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40981","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:00:15.193Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-431","primary_source":"","published":"2026-05-07T03:55:43.600Z"},{"affected":"3.1.0 < 3.1.14; 4.1.0 < 4.1.10; 4.2.0 < 4.2.7; 4.3.0 < 4.3.3; 5.0.0 < 5.0.3","affected_versions_present":true,"cve_id":"CVE-2026-41002","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41002","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-09T03:55:58.649Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-431","primary_source":"","published":"2026-05-07T03:53:18.269Z"},{"affected":"3.1.0 < 3.1.14; 4.1.0 < 4.1.10; 4.2.0 < 4.2.7; 4.3.0 < 4.3.3; 5.0.0 < 5.0.3","affected_versions_present":true,"cve_id":"CVE-2026-41004","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41004","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-07T12:56:31.413Z","patch_url":"","primary_source":"","published":"2026-05-07T03:51:31.920Z"},{"affected":"3.1.0 < 3.1.14; 4.1.0 < 4.1.10; 4.2.0 < 4.2.7; 4.3.0 < 4.3.3; 5.0.0 < 5.0.3","affected_versions_present":true,"cve_id":"CVE-2026-40982","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-40982","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:00:13.424Z","patch_url":"https://www.cyber.gc.ca/en/alerts-advisories/spring-security-advisory-av26-431","primary_source":"","published":"2026-05-07T03:49:30.065Z"},{"affected":"4.2.x < 4.2.2; 4.1.x < 4.1.6; 4.0.x < 4.0.10; 3.1.x < 3.1.10; 3.0.x < 4.1.6; 2.2.x < 4.1.6","affected_versions_present":true,"cve_id":"CVE-2025-22232","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-22232","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-04-10T18:08:28.560Z","patch_url":"","primary_source":"","published":"2025-04-10T17:26:56.755Z"},{"affected":"2.0 < v2.0.4.RELEASE; 1.4 < v1.4.6.RELEASE; 2.1 < v2.1.2.RELEASE","affected_versions_present":true,"cve_id":"CVE-2019-3799","cve_url":"https://cve.blacktree.nl/cve/CVE-2019-3799","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-17T00:16:21.820Z","patch_url":"https://www.oracle.com/security-alerts/cpuapr2022.html","primary_source":"","published":"2019-05-06T15:21:37.135Z"}],"source_generated_at":"2026-10-07T06:21:30.017Z","vendor":"Spring"}}
