Sensitive Data Logging Issue in Spring Cloud Function by VMware
CVE-2026-59301

3.1LOW

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59301?

The Spring Cloud Function framework, utilized for building serverless applications, is susceptible to a vulnerability that may allow logging of sensitive data when used with Azure. This could expose sensitive information unintentionally, thereby increasing the risk of data breaches. Users of the affected versions should take immediate action to mitigate this vulnerability by updating to the latest versions to ensure that sensitive data remains protected.

Affected Version(s)

Spring Cloud Function 5.0.0 <= 5.0.3

Spring Cloud Function 4.3.0 <= 4.3.4

Spring Cloud Function 4.2.0 <= 4.2.7

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.