Vulnerability Intelligence Report
Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVN
CVE-2026-47836
The base directory (spring.cloud.config.server.svn.basedir) used by the Spring Cloud Config Server to clone SVN repositories to is susceptible to time-of-check-time-of-use (TOCTOU) attacks. Spring Cloud Config 5.0.0 - 5.0.4 Spring Cloud Config 4.3.0 - 4.3.4 Spring Cloud Config 4.0.0 - 4.2.8 Spring Cloud Config 3.1.14 and earlier
No Active Exploit Signals
CVSS Base Score
7.2
HIGH
Exploitability:0.9
Impact Score:5.8
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-367 ↗CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Spring | Spring Cloud Config | 5.0.0 <= 5.0.4 (affected), 4.3.0 <= 4.3.4 (affected), 4.0.0 <= 4.2.8 (affected), 0 <= 3.1.14 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | VMware by Broadcom · Vendor · USA |
| Reserved | 2026-05-20T10:00:51 |
| Published | 2026-08-26T17:05:21 |
| Last Updated | 2026-08-27T03:58:24 |
Community Chatter & Buzz