Protection mechanism failure in Spring Cloud Function - CVE-2026-59297
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information or affect integrity checks.
The vulnerability exists due to improper security check implementation in the isSecure() implementation of ServerlessHttpServletRequest when determining whether a URI is secure. A remote privileged user can cause the application to incorrectly treat a URI as secure to disclose sensitive information or affect integrity checks.
User interaction is required.