← Vulnerability feed

Vulnerability record · CVE-2026-59298 · published 27 August 2026

CVE-2026-59298: Vmware spring cloud function improper input validation vulnerability

Vmware · Spring Cloud Function

Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier

3.5 CVSS 3.1 Low EPSS 0.22% · top 88.1% CWE-20 · Improper input validation
3.5CVSS 3.1 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
2 Sep 2026Last modified by NVD

Description

Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://spring.io/security/cve-2026-59298 PatchVendor Advisory

Track CVE-2026-59298 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-22963Spring Cloud Function routing expression SpEL injection RCESpring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions allow a user to supply a crafted SpEL expression as a routing-expression w…KEVEPSS 100%analysed7.5CVE-2022-22979Vmware spring cloud function allocation without limits vulnerabilityIn Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to ca…EPSS 1.4%6.5CVE-2026-40989Vmware spring cloud function vulnerabilityUnder infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versions: Spring Cloud Function 3.2…EPSS 0.28%6.5CVE-2026-40990Vmware spring cloud function allocation without limits vulnerabilityOOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud …EPSS 0.28%5.5CVE-2026-59291Vmware spring cloud function server-side request forgery (ssrf) vulnerabilityPotential arbitrary file read and SSRF vulnerability in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.…EPSS 0.25%4.9CVE-2026-59301Vmware spring cloud function sensitive information in log file vulnerabilityPotential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring C…EPSS 0.23%4.9CVE-2026-59302Vmware spring cloud function sensitive information in log file vulnerabilityPotential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream …EPSS 0.17%3.5CVE-2026-59299Vmware spring cloud function vulnerabilityComposition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4…EPSS 0.21%

Source: NIST National Vulnerability Database (record CVE-2026-59298), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.