Inclusion of Sensitive Information in Log Files in Spring Cloud Function - CVE-2026-59301
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to sensitive information exposure in Spring Cloud Function Azure when handling function invocations that are logged. A remote privileged user can trigger logging of sensitive data to disclose sensitive information.
User interaction is required.