CVE-2026-59299: VMware Spring Cloud Function
Low severity, CVSS 3.5. EPSS: 0.2% chance of exploitation in the next 30 days.
Composition lookup can potentially poison base function in Spring Cloud Function. Spring Cloud Function 5.0.0 - 5.0.3 Spring Cloud Function 4.3.0 - 4.3.4 Spring Cloud Function 4.2.0 - 4.2.7 Spring Cloud Function 3.2.16 and earlier
Affected products
- VMware Spring Cloud Function: from 3.2.0, before 3.2.17 (fixed in 3.2.17); from 4.2.0, before 4.2.8 (fixed in 4.2.8); from 4.3.0, before 4.3.5 (fixed in 4.3.5); from 5.0.0, before 5.0.4 (fixed in 5.0.4)
Published 2026-08-27. Last modified 2026-09-02.