CVE-2026-59300: Potential for logging sensitive data in Spring Cloud Function AWS
Published Aug 27, 2026
·Updated
Potential for logging sensitive data in Spring Cloud Function AWS. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier
Affected Software
5 affected components
Spring Spring Cloud Function AWS>=5.0.0<=5.0.3, >=4.3.0<=4.3.4, >=4.2.0<=4.2.7, <=3.2.16
VMware Spring Cloud Function>=3.2.0<3.2.17
VMware Spring Cloud Function>=4.2.0<4.2.8
VMware Spring Cloud Function>=4.3.0<4.3.5
VMware Spring Cloud Function>=5.0.0<5.0.4
Remediation
Patch Available
Event History
Aug 27, 2026
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which deployments should be reviewed?
Review Spring Cloud Function AWS deployments using Spring Cloud Function 5.0.0 through 5.0.3, 4.3.0 through 4.3.4, 4.2.0 through 4.2.7, or 3.2.16 and earlier.
2
What does exploitation require?
The supplied vector indicates network reachability, high attack complexity, high privileges, and user interaction are required. The data does not identify the specific privileges or interaction involved.
3
What is the expected security impact?
The issue is rated low severity with low confidentiality and integrity impact and no availability impact. It concerns the potential logging of sensitive data.