CVE-2026-59301: Potential for logging sensitive data in Spring Cloud Function Azure
Published Aug 27, 2026
·Updated
Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7
Affected Software
3 affected components
Spring Cloud Function>=5.0.0<=5.0.3
Spring Cloud Function>=4.3.0<=4.3.4
Spring Cloud Function>=4.2.0<=4.2.7
Event History
Aug 27, 2026
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverity
Frequently Asked Questions
1
What level of access and interaction are required for exploitation?
The CVSS vector indicates network reachability, high attack complexity, high privileges, and user interaction are required. This is not characterized as a low-effort unauthenticated remote attack.
2
What is the expected security impact if exploited?
The reported impact is low confidentiality impact and low integrity impact, with no availability impact indicated.