VendorsVMwarespring_cloud_functionall versions
Vulnerabilities

VMware Spring Cloud Function

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2022-22963
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution and access to local resources.
Published 2022-04-01 · Analyzed
9.8KEV1 PoCEPSS 0.999
CVE-2022-22979
In Spring Cloud Function versions prior to 3.2.6, it is possible for a user who directly interacts with framework provided lookup functionality to cause a denial-of-service condition due to the caching issue in the Function Catalog component of the framework.
Published 2022-06-21 · Modified
7.5EPSS 0.014
CVE-2026-40989
Self Routing guard bypassed via function composition
Published 2026-06-01 · Analyzed
6.5EPSS 0.002
CVE-2026-40990
Unbounded cache for function definitions
Published 2026-06-01 · Analyzed
6.5EPSS 0.002
CVE-2026-59291
Potential arbitrary file read and SSRF vulnerability in Spring Cloud Function
Published 2026-08-27 · Analyzed
5.5EPSS 0.002
CVE-2026-59301
Potential for logging sensitive data in Spring Cloud Function Azure
Published 2026-08-27 · Analyzed
4.9EPSS 0.002
CVE-2026-59302
Potential for logging sensitive data in Spring Cloud Stream
Published 2026-08-27 · Analyzed
4.9EPSS 0.002
CVE-2026-59298
Potential for improper filtering of HTTP headers in Spring Cloud Function
Published 2026-08-27 · Analyzed
3.5EPSS 0.002
CVE-2026-59299
Composition lookup can potentially poison base function in Spring Cloud Function
Published 2026-08-27 · Analyzed
3.5EPSS 0.002
CVE-2026-59300
Potential for logging sensitive data in Spring Cloud Function AWS
Published 2026-08-27 · Analyzed
3.5EPSS 0.002
CVE-2026-59297
Spring Cloud Function can incorrectly determine if URI is secure
Published 2026-08-27 · Analyzed
3.5EPSS 0.001