Arbitrary File Read and SSRF Vulnerability in Spring Cloud Function by VMware
CVE-2026-59291
2LOW
What is CVE-2026-59291?
An arbitrary file read and Server-Side Request Forgery (SSRF) vulnerability has been identified in Spring Cloud Function, affecting multiple versions. This issue allows an attacker to read files on the server or manipulate server requests, potentially leading to unauthorized data access or further exploitation of the affected environment. Users of Spring Cloud Function versions 5.0.0 to 5.0.3 and 4.2.0 to 4.3.4 are advised to apply security updates provided by VMware to mitigate these risks.
Affected Version(s)
Spring Cloud Function 5.0.0 <= 5.0.3
Spring Cloud Function 4.3.0 <= 4.3.4
Spring Cloud Function 4.2.0 <= 4.2.7
