CVE-2026-59297

Summary

Implementation of isSecure() call of ServerlessHttpServletRequest does not verify the actual scheme. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7

Affected Software

VendorProductVersion RangeStatus
SpringSpring Cloud Function5.0.0 <= 5.0.3affected
SpringSpring Cloud Function4.3.0 <= 4.3.4affected
SpringSpring Cloud Function4.2.0 <= 4.2.7affected

Weaknesses

  • CWE-346 Origin Validation Error

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References