In spring-cloud-kubernetes-client-config, dependencies protobuf (CVE-2024-7254) and jose4j (CVE-2023-51775) have DOS CVE's associated with them from io.kubernetes:client-java:19.0.2
It appears the latest release of 3.3.0 is still using 19.0.2 of the client-java library
This issue is corrected in versions greater than 19.0.2 of client-java