ServerlessHttpServletRequest Implementation Flaw in Spring Cloud Function
CVE-2026-59297
3.1LOW
What is CVE-2026-59297?
The implementation of the isSecure() method in ServerlessHttpServletRequest fails to properly verify the actual scheme being used. This oversight can potentially expose applications utilizing Spring Cloud Function to security risks, allowing unauthorized access or misrouting of requests. This affects multiple versions of the product, necessitating prompt updates and patches by users to mitigate any potential threats.
Affected Version(s)
Spring Cloud Function 5.0.0 <= 5.0.3
Spring Cloud Function 4.3.0 <= 4.3.4
Spring Cloud Function 4.2.0 <= 4.2.7
