Resource Exhaustion Vulnerability in Spring Cloud Function Products
CVE-2026-40989

5.7MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
1 June 2026

What is CVE-2026-40989?

A vulnerability in the routing layer of Spring Cloud Function products can lead to infinite recursion during request handling. This can cause an Out of Memory (OOM) error, potentially disrupting the performance and availability of applications using affected versions. It is recommended that users upgrade to the latest versions to mitigate this issue.

Affected Version(s)

Spring Cloud Function 3.2.0 < 3.2.16

Spring Cloud Function 4.1.0 < 4.1.10

Spring Cloud Function 4.2.0 < 4.2.6

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.