ServerlessHttpServletRequest Implementation Flaw in Spring Cloud Function
CVE-2026-59297

3.1LOW

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59297?

The implementation of the isSecure() method in ServerlessHttpServletRequest fails to properly verify the actual scheme being used. This oversight can potentially expose applications utilizing Spring Cloud Function to security risks, allowing unauthorized access or misrouting of requests. This affects multiple versions of the product, necessitating prompt updates and patches by users to mitigate any potential threats.

Affected Version(s)

Spring Cloud Function 5.0.0 <= 5.0.3

Spring Cloud Function 4.3.0 <= 4.3.4

Spring Cloud Function 4.2.0 <= 4.2.7

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.