CVE-2026-59297: Spring Cloud Function can incorrectly determine if URI is secure
Published Aug 27, 2026
·Updated
Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7
Affected Software
1 affected component
Spring Spring Cloud Function>=5.0.0<=5.0.3, >=4.3.0<=4.3.4, >=4.2.0<=4.2.7
Event History
Aug 27, 2026
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverity
Frequently Asked Questions
1
Which deployments are affected?
Affected versions are Spring Cloud Function 5.0.0 through 5.0.3, 4.3.0 through 4.3.4, and 4.2.0 through 4.2.7.
2
What level of attacker access is required?
The CVSS vector indicates that exploitation is network-accessible but requires high privileges and user interaction. Exploitation also has high attack complexity.
3
What is the potential impact?
The reported impact is low confidentiality and integrity impact, with no availability impact. The vulnerability is rated low severity with a CVSS score of 3.1.