Description
Potential for improper filtering of HTTP headers in Spring Cloud Function.
Spring Cloud Function 5.0.0 - 5.0.3
Spring Cloud Function 4.3.0 - 4.3.4
Spring Cloud Function 4.2.0 - 4.2.7
Spring Cloud Function 3.2.16 and earlier
Published: 2026-08-27
Score: 3.1 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Spring Cloud Function suffers from inadequate filtering of HTTP headers, which may allow attackers to inject or manipulate headers in outgoing responses. The vulnerability could enable header injection attacks, but the description does not specify the exact security consequences; it is inferred that downstream vulnerabilities such as HTTP response splitting or information disclosure could result.

Affected Systems

Users deploying Spring Cloud Function version 5.0.0 through 5.0.3, 4.3.0 through 4.3.4, 4.2.0 through 4.2.7, or 3.2.16 and earlier are affected.

Risk and Exploitability

The CVSS score of 3.1 indicates low severity. EPSS is unavailable, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote exploitation via crafted HTTP requests sent to affected function endpoints, allowing attackers to inject or manipulate response headers.

Generated by OpenCVE AI on August 28, 2026 at 08:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a non‑vulnerable release – 5.0.4 or newer, 4.3.5 or newer, 4.2.8 or newer, or 3.2.17 or newer.
  • If an upgrade is not immediately possible, enforce strict header filtering (either in application code or via a reverse proxy) before responses are sent.
  • Ensure your dependency management pins the Spring Cloud Function library to a non‑vulnerable version, preventing accidental use of older releases in microservice deployments.

Generated by OpenCVE AI on August 28, 2026 at 08:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 28 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Spring
Spring spring Cloud Function
Vendors & Products Spring
Spring spring Cloud Function

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description Potential for improper filtering of HTTP headers in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier
Title Potential for improper filtering of HTTP headers in Spring Cloud Function
References
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N'}


Subscriptions

Spring Spring Cloud Function
cve-icon MITRE

Status: PUBLISHED

Assigner: vmware

Published:

Updated: 2026-08-27T17:57:55.073Z

Reserved: 2026-07-04T18:13:34.323Z

Link: CVE-2026-59298

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T20:17:56.060

Modified: 2026-08-27T20:17:56.060

Link: CVE-2026-59298

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T06:30:18Z

Weaknesses

No weakness.