Junglewise Threat Intelligence

CVE-2026-59298: Spring Cloud Function improper HTTP header filtering

CVE-2026-59298 · Severity: low · CVSS 3.1 · Published 2026-08-27

Technologies: Spring Cloud Function. Vendors: Spring.

Executive brief

Spring Cloud Function is a framework for building serverless applications in Spring. Improper filtering of HTTP headers could allow attackers to manipulate request handling or bypass security controls, potentially leading to unauthorized access or information disclosure in applications relying on header-based security policies.

Technical details

This vulnerability stems from improper filtering of HTTP headers in Spring Cloud Function's request processing logic. The flaw affects multiple versions across the 3.x, 4.x, and 5.x release lines. An attacker with network access to an affected application can craft malicious HTTP requests with specially crafted headers to bypass intended security controls or manipulate application behavior. The vulnerability is network-reachable and requires no authentication. Patches are available in newer versions beyond those listed as affected.

Affected products

  • Spring Cloud Function 3.2.16 and earlier, 4.2.0–4.2.7, 4.3.0–4.3.4, 5.0.0–5.0.3

Timeline

  • 2026-08-27: disclosed

References

Related threats