CVE-2026-41002 is a high-severity time-of-check-time-of-use (TOCTOU) race condition in Spring Cloud Config Server’s Git repository cloning workflow. The issue affects handling of the spring.cloud.config.server.git.basedir setting, which defines the local filesystem directory used to clone Git repositories that back configuration delivery. The vulnerable logic performs a check on the base directory and then uses it in a later, non-atomic operation, creating a race window in which a locally privileged attacker can alter or replace the directory before it is used. Available reporting indicates this could be achieved through filesystem manipulation such as directory replacement or symlink substitution, potentially redirecting clone operations to an attacker-controlled location. Affected versions are Spring Cloud Config 3.1.0 through 3.1.13, 4.1.0 through 4.1.9, 4.2.0 through 4.2.6, 4.3.0 through 4.3.2, and 5.0.0 through 5.0.2.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
spring.cloud.config.server.git.basedir path and its parent directories, avoid shared-host or multi-tenant deployments where untrusted local users or processes can manipulate the filesystem, and monitor for unexpected symlink or directory changes affecting the Git clone base directory. No specific vendor mitigation beyond upgrading was provided in the available content.Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A high-severity TOCTOU race condition in Spring Cloud Config Server affecting the base directory used to clone Git repositories, allowing file manipulation during the cloning process.
A TOCTOU vulnerability affecting Spring Cloud Config Server.
A high-severity TOCTOU race condition in Spring Cloud Config Server's Git repository cloning/base directory handling that can let a locally privileged attacker manipulate the configuration storage directory and expose or alter sensitive configuration data.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.