Spring Cloud Function Vulnerability Affecting Multiple Versions by Spring
CVE-2026-59299

3.1LOW

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59299?

A composition lookup vulnerability in Spring Cloud Function allows malicious input to potentially poison the base function. This could lead to unauthorized access or manipulation of application behavior, exposing systems to risks. Versions impacted include Spring Cloud Function 5.0.0 through 5.0.3, as well as 4.2.0 to 4.2.7 and earlier releases. Users are advised to review their configurations and apply necessary updates to mitigate this vulnerability.

Affected Version(s)

Spring Cloud Function 5.0.0 <= 5.0.3

Spring Cloud Function 4.3.0 <= 4.3.4

Spring Cloud Function 4.2.0 <= 4.2.7

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.