Arbitrary File Read and SSRF Vulnerability in Spring Cloud Function by VMware
CVE-2026-59291

2LOW

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59291?

An arbitrary file read and Server-Side Request Forgery (SSRF) vulnerability has been identified in Spring Cloud Function, affecting multiple versions. This issue allows an attacker to read files on the server or manipulate server requests, potentially leading to unauthorized data access or further exploitation of the affected environment. Users of Spring Cloud Function versions 5.0.0 to 5.0.3 and 4.2.0 to 4.3.4 are advised to apply security updates provided by VMware to mitigate these risks.

Affected Version(s)

Spring Cloud Function 5.0.0 <= 5.0.3

Spring Cloud Function 4.3.0 <= 4.3.4

Spring Cloud Function 4.2.0 <= 4.2.7

References

CVSS V3.1

Score:
2
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.