CVE-2026-59298: Potential for improper filtering of HTTP headers in Spring Cloud Function
Published Aug 27, 2026
·Updated
Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier
Affected Software
4 affected components
Spring Spring Cloud Function>=5.0.0<=5.0.3
Spring Spring Cloud Function>=4.3.0<=4.3.4
Spring Spring Cloud Function>=4.2.0<=4.2.7
Spring Spring Cloud Function<=3.2.16
Event History
Aug 27, 2026
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverity
Frequently Asked Questions
1
Which Spring Cloud Function versions are affected?
Affected versions are 5.0.0 through 5.0.3, 4.3.0 through 4.3.4, 4.2.0 through 4.2.7, and 3.2.16 and earlier.
2
What access and conditions does an attacker need?
The CVSS vector indicates network reachability, but exploitation has high attack complexity, requires high privileges, and requires user interaction.
3
What is the potential impact?
The issue may allow limited disclosure and limited modification of information. The supplied vector indicates no availability impact and no scope change.