Improper HTTP Header Filtering in Spring Cloud Function by Spring
CVE-2026-59298

3.1LOW

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59298?

A vulnerability exists in Spring Cloud Function due to improper filtering of HTTP headers. This flaw can be exploited to manipulate how HTTP headers are processed by the system, which may lead to unintended behavior or security breaches. Affected versions include Spring Cloud Function from 3.2.16 to 5.0.3, with several releases in between. It is vital for users of these versions to assess their systems and apply appropriate patches or mitigations as recommended.

Affected Version(s)

Spring Cloud Function 5.0.0 <= 5.0.3

Spring Cloud Function 4.3.0 <= 4.3.4

Spring Cloud Function 4.2.0 <= 4.2.7

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.