CVE-2026-59299CWE-471

CVE-2026-59299

Low · published August 28, 2026

CVSS v3.1
3.1
EPSS
0%
Percentile
4.6
In the wild
Unconfirmed
What it is

Composition lookup can potentially poison base function in Spring Cloud Function.

Spring Cloud Function 5.0.0 - 5.0.3

Spring Cloud Function 4.3.0 - 4.3.4

Spring Cloud Function 4.2.0 - 4.2.7

Spring Cloud Function 3.2.16 and earlier

The record
Technical detail
CVSS v3.1
3.1 · LOW
Vector
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00151 · 4.6th percentile
Weakness
CWE-471 · Modification of Assumed-Immutable Data (MAID)
Published
2026-08-28T00:17Z
Affected products (4)
ProductVersionsFixed in
vmware/spring_cloud_function≥ 3.2.0, < 3.2.173.2.17
vmware/spring_cloud_function≥ 4.2.0, < 4.2.84.2.8
vmware/spring_cloud_function≥ 4.3.0, < 4.3.54.3.5
vmware/spring_cloud_function≥ 5.0.0, < 5.0.45.0.4
References (1)
EPSS history
Timeline
  • 27 AUG 17:57Z
    Composition lookup can potentially poison base function in Spring Cloud Function
    cvelistv5