PT-2026-82705 · Spring+2 · Spring Cloud Function

CVE-2026-59297

·

Published

2026-08-27

·

Updated

2026-08-27

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Spring Cloud Function versions 5.0.0 through 5.0.3 Spring Cloud Function versions 4.3.0 through 4.3.4 Spring Cloud Function versions 4.2.0 through 4.2.7
Description The isSecure() function within the ServerlessHttpServletRequest class fails to verify the actual scheme used for the request.
Recommendations Update Spring Cloud Function to a version later than 5.0.3. Update Spring Cloud Function to a version later than 4.3.4. Update Spring Cloud Function to a version later than 4.2.7.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59297

Affected Products

Spring Cloud Function