CVE-2026-59301
Analyzed Analyzed - Analysis Complete

Logging Sensitive Data in Spring Cloud Function

Vulnerability report for CVE-2026-59301, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-09-04

Assigner: VMware

Description

Potential for logging sensitive data in Spring Cloud Function Azure. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-09-04
Generated
2026-09-17
AI Q&A
2026-08-28
EPSS Evaluated
2026-09-15
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
vmware spring_cloud_function From 5.0.0 (inc) to 5.0.4 (exc)
vmware spring_cloud_function From 4.2.0 (inc) to 4.2.8 (exc)
vmware spring_cloud_function From 4.3.0 (inc) to 4.3.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves Spring Cloud Function Azure potentially logging sensitive data. It affects versions 5.0.0-5.0.3, 4.3.0-4.3.4, and 4.2.0-4.2.7. The issue arises when sensitive information is inadvertently included in logs during function execution.

Detection Guidance

To detect this vulnerability, check if your system is running affected versions of Spring Cloud Function (5.0.0-5.0.3, 4.3.0-4.3.4, or 4.2.0-4.2.7). Use commands like 'find / -name spring-cloud-function-*.jar' to locate the library. Verify version details in the JAR manifest or logs.

Impact Analysis

If exploited, this vulnerability could expose sensitive data in logs, leading to unauthorized access or compliance violations. The impact is limited due to high attack complexity and requires user interaction, but sensitive data exposure remains a risk.

Compliance Impact

Logging sensitive data may violate GDPR and HIPAA requirements for data protection and confidentiality. Organizations using affected versions could face compliance penalties if sensitive data is exposed through logs.

Mitigation Strategies

Upgrade to fixed versions: Spring Cloud Function 5.0.4 for OSS, or 4.3.5 and 4.2.8 for Enterprise Support. No additional mitigation steps are required.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59301. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart