Uncontrolled Recursion in Spring Cloud Function - CVE-2026-40989
Published: May 11, 2026
Spring Cloud Function
VMware, Inc
Description
The vulnerability allows an attacker with physical access to cause a denial of service.
The vulnerability exists due to improper control of recursion in the routing layer when handling self-composed functions. An attacker with physical access can trigger infinite recursion in request handling to cause a denial of service.
User interaction is required.