diff --git a/advisories/github-reviewed/2026/05/GHSA-6g23-24mc-hx6x/GHSA-6g23-24mc-hx6x.json b/advisories/github-reviewed/2026/05/GHSA-6g23-24mc-hx6x/GHSA-6g23-24mc-hx6x.json index ca4cd8a510a94..c07e4a7461db0 100644 --- a/advisories/github-reviewed/2026/05/GHSA-6g23-24mc-hx6x/GHSA-6g23-24mc-hx6x.json +++ b/advisories/github-reviewed/2026/05/GHSA-6g23-24mc-hx6x/GHSA-6g23-24mc-hx6x.json @@ -1,7 +1,7 @@ { "schema_version": "1.4.0", "id": "GHSA-6g23-24mc-hx6x", - "modified": "2026-06-11T14:50:14Z", + "modified": "2026-06-11T14:50:15Z", "published": "2026-05-07T06:31:41Z", "aliases": [ "CVE-2026-40982" @@ -25,10 +25,10 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "0" + "introduced": "4.1.0" }, { - "last_affected": "3.1.13" + "last_affected": "4.1.9" } ] } @@ -44,10 +44,10 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "4.1.0" + "introduced": "4.2.0" }, { - "last_affected": "4.1.9" + "last_affected": "4.2.6" } ] } @@ -63,14 +63,17 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "4.2.0" + "introduced": "4.3.0" }, { - "last_affected": "4.2.6" + "fixed": "4.3.3" } ] } - ] + ], + "database_specific": { + "last_known_affected_version_range": "<= 4.3.2" + } }, { "package": { @@ -82,16 +85,16 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "4.3.0" + "introduced": "5.0.0" }, { - "fixed": "4.3.3" + "fixed": "5.0.3" } ] } ], "database_specific": { - "last_known_affected_version_range": "<= 4.3.2" + "last_known_affected_version_range": "<= 5.0.2" } }, { @@ -104,17 +107,33 @@ "type": "ECOSYSTEM", "events": [ { - "introduced": "5.0.0" + "introduced": "1.1.0" }, { - "fixed": "5.0.3" + "last_affected": "3.1.13" } ] } - ], - "database_specific": { - "last_known_affected_version_range": "<= 5.0.2" - } + ] + }, + { + "package": { + "ecosystem": "Maven", + "name": "org.springframework.cloud:spring-cloud-config-server" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "4.0.0" + }, + { + "last_affected": "4.0.5" + } + ] + } + ] } ], "references": [ @@ -122,6 +141,10 @@ "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-40982" }, + { + "type": "WEB", + "url": "https://github.com/spring-cloud/spring-cloud-config/commit/62846bda84793307ca7f5edd927e7d37d2b6f1ef" + }, { "type": "PACKAGE", "url": "https://github.com/spring-cloud/spring-cloud-config"