CVE-2026-40989: Self Routing guard bypassed via function composition
Under infinite recursion in the routing layer, request-handling can cause OOM error.
Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Function 4.1.x: versions prior to 4.1.10 Spring Cloud Function 4.2.x: versions prior to 4.2.6 Spring Cloud Function 4.3.x: versions prior to 4.3.3 Spring Cloud Function 5.0.x: versions prior to 5.0.2 Older, unsupported versions are also affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Spring Cloud Function 3.2.xto a version that resolves this vulnerability.Fixed in 3.2.16 - Upgrade
Upgrade
Spring Cloud Function 4.1.xto a version that resolves this vulnerability.Fixed in 4.1.10 - Upgrade
Upgrade
Spring Cloud Function 4.2.xto a version that resolves this vulnerability.Fixed in 4.2.6 - Upgrade
Upgrade
Spring Cloud Function 4.3.xto a version that resolves this vulnerability.Fixed in 4.3.3 - Upgrade
Upgrade
Spring Cloud Function 5.0.xto a version that resolves this vulnerability.Fixed in 5.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40989?
CVE-2026-40989 has a medium severity rating of 5.7.
How do I fix CVE-2026-40989?
To remediate CVE-2026-40989, upgrade to Spring Cloud Function version 3.2.16, 4.1.10, or 4.2.6 or later.
What type of vulnerability is CVE-2026-40989?
CVE-2026-40989 is a self-routing guard bypass vulnerability caused by infinite recursion in the routing layer.
What are the potential impacts of CVE-2026-40989?
CVE-2026-40989 can lead to an Out Of Memory (OOM) error due to excessive request handling.
Which versions of Spring Cloud Function are affected by CVE-2026-40989?
CVE-2026-40989 affects Spring Cloud Function versions prior to 3.2.16, 4.1.10, and 4.2.6.