Incomplete List of Disallowed Inputs in Spring Cloud Function - CVE-2026-59298

 

Incomplete List of Disallowed Inputs in Spring Cloud Function - CVE-2026-59298

Published: August 31, 2026


Vulnerability identifier: #VU146389
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59298
CWE-ID: CWE-184
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information and affect the integrity of HTTP header handling.

The vulnerability exists due to improper filtering in HTTP headers in Spring Cloud Function when handling HTTP requests. A remote privileged user can send a specially crafted request to disclose sensitive information and affect the integrity of HTTP header handling.

User interaction is required.


Affected software

Spring Cloud Function

How to mitigate CVE-2026-59298

Install security update from vendor's website.

Spring Cloud Function - addressed in versions 3.2.17, 4.2.8, 4.3.5, 5.0.4

External References

Related Security Bulletins