CVE-2026-59302
- EPSS 0.15%
- Veröffentlicht 27.08.2026 17:57:58
- Zuletzt bearbeitet 23.09.2026 16:17:44
Potential for logging sensitive data in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6
CVE-2026-59300
- EPSS 0.15%
- Veröffentlicht 27.08.2026 17:57:57
- Zuletzt bearbeitet 02.09.2026 00:37:26
Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier
CVE-2026-59301
- EPSS 0.15%
- Veröffentlicht 27.08.2026 17:57:57
- Zuletzt bearbeitet 04.09.2026 19:20:30
Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7
CVE-2026-59299
- EPSS 0.15%
- Veröffentlicht 27.08.2026 17:57:56
- Zuletzt bearbeitet 02.09.2026 00:44:37
Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier
CVE-2026-59298
- EPSS 0.16%
- Veröffentlicht 27.08.2026 17:57:55
- Zuletzt bearbeitet 02.09.2026 00:49:21
Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier
CVE-2026-59297
- EPSS 0.08%
- Veröffentlicht 27.08.2026 17:57:53
- Zuletzt bearbeitet 02.09.2026 17:27:35
Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7
CVE-2026-59291
- EPSS 0.16%
- Veröffentlicht 27.08.2026 17:57:48
- Zuletzt bearbeitet 31.08.2026 23:02:59
Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7
CVE-2026-40990
- EPSS 0.21%
- Veröffentlicht 01.06.2026 17:49:16
- Zuletzt bearbeitet 22.07.2026 07:10:00
OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Function 4.1.x: versions prior to 4.1.10 Sprin...
CVE-2026-40989
- EPSS 0.21%
- Veröffentlicht 01.06.2026 17:49:14
- Zuletzt bearbeitet 22.07.2026 07:10:00
Under infinite recursion in the routing layer, request-handling can cause OOM error. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Function 4.1.x: versions prior to 4.1.10 Spring Cloud Func...
CVE-2024-22271
- EPSS 0.36%
- Veröffentlicht 09.07.2024 13:15:09
- Zuletzt bearbeitet 15.04.2026 00:35:42
In Spring Cloud Function framework, versions 4.1.x prior to 4.1.2, 4.0.x prior to 4.0.8 an application is vulnerable to a DOS attack when attempting to compose functions with non-existing functions. Specifically, an application is vulnerable when al...