CVE-2026-59298
Received Received - Intake

Improper Header Filtering in Spring Cloud Function

Vulnerability report for CVE-2026-59298, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: VMware

Description

Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-28
AI Q&A
2026-08-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 8 associated CPEs
Vendor Product Version / Range
vmware spring_cloud_function From 3.2.16 (inc) to 5.0.3 (inc)
vmware spring_cloud_function to 5.0.3 (inc)
vmware spring_cloud_function to 4.3.4 (inc)
vmware spring_cloud_function to 4.2.7 (inc)
vmware spring_cloud_function From 5.0.0 (inc) to 5.0.3 (inc)
vmware spring_cloud_function From 4.3.0 (inc) to 4.3.4 (inc)
vmware spring_cloud_function From 4.2.0 (inc) to 4.2.7 (inc)
vmware spring_cloud_function to 3.2.16 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-59298 is a vulnerability in Spring Cloud Function where HTTP headers are not properly filtered. This could allow improper handling of headers in affected versions.

Detection Guidance

To detect this vulnerability, check the installed version of Spring Cloud Function in your system. Compare it against the affected versions: 5.0.0-5.0.3, 4.3.0-4.3.4, 4.2.0-4.2.7, or 3.2.16 and earlier. Use commands like 'find / -name spring-cloud-function-*.jar' to locate the JAR file and 'java -jar spring-cloud-function-*.jar --version' to check the version.

Impact Analysis

The impact is limited due to low severity. It may lead to improper header processing, potentially causing unexpected behavior in applications using vulnerable versions.

Compliance Impact

The vulnerability involves improper filtering of HTTP headers in Spring Cloud Function, which could potentially allow unauthorized access to sensitive data. This may impact compliance with GDPR (data protection) and HIPAA (healthcare data privacy) by increasing the risk of data breaches or unauthorized disclosures. Affected organizations should assess their exposure and apply mitigations such as upgrading to patched versions.

Mitigation Strategies

Upgrade to the fixed versions immediately: 5.0.4 for OSS or 4.3.5, 4.2.8, and 3.2.17 for enterprise support users. No additional mitigation steps are required beyond upgrading as per the advisory.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59298. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart