Incomplete List of Disallowed Inputs in Spring Cloud Function - CVE-2026-59298
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information and affect the integrity of HTTP header handling.
The vulnerability exists due to improper filtering in HTTP headers in Spring Cloud Function when handling HTTP requests. A remote privileged user can send a specially crafted request to disclose sensitive information and affect the integrity of HTTP header handling.
User interaction is required.