Sensitive Data Logging Vulnerability in Spring Cloud Function by Pivotal Software
CVE-2026-59300

3.1LOW

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59300?

This vulnerability in Spring Cloud Function exposes a risk of logging sensitive data in applications using the framework. Versions 5.0.0 to 5.0.3, 4.3.0 to 4.3.4, and 4.2.0 to 4.2.7, along with all versions of 3.2.16 and earlier, are impacted. This issue allows attackers to potentially access sensitive information that could be exploited if proper safeguards are not in place.

Affected Version(s)

Spring Cloud Function 5.0.0 <= 5.0.3

Spring Cloud Function 4.3.0 <= 4.3.4

Spring Cloud Function 4.2.0 <= 4.2.7

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.