Detects Spring Cloud Config Servers vulnerable to directory traversal via the profile URL segment. The environment and resource endpoints validate the name and label parameters for path traversal but skip the profile parameter. An attacker injects encoded dot-dot sequences to escape the configured search directory and read arbitrary configuration files, database credentials, and API keys from the server filesystem.
Is your app exploitable through CVE-2026-22739?
Scan your domain free