Junglewise Threat Intelligence

CVE-2026-59291: Spring Cloud Function arbitrary file read and SSRF

CVE-2026-59291 · Severity: low · CVSS 2 · Published 2026-08-27

Technologies: VMware Spring Cloud Function. Vendors: VMware.

Executive brief

Spring Cloud Function is a framework used to build serverless applications that process events or HTTP requests. This vulnerability allows attackers to read arbitrary files from the server and potentially make unauthorized requests to internal systems (SSRF), potentially exposing sensitive configuration data or enabling lateral movement within a network.

Technical details

This vulnerability in Spring Cloud Function allows arbitrary file read and server-side request forgery (SSRF) attacks. The exact attack vector and vulnerable component are not fully detailed in the advisory reference material provided, but the issue affects multiple versions: 5.0.0–5.0.3, 4.3.0–4.3.4, and 4.2.0–4.2.7. The vulnerability is likely network-reachable and may require specific request manipulation or function invocation. Attackers can exploit this to access sensitive files on the server filesystem or trigger requests to internal resources.

Affected products

  • VMware Spring Cloud Function 4.2.0–4.2.7, 4.3.0–4.3.4, 5.0.0–5.0.3

Timeline

  • 2026-08-27: disclosed

References

Related threats