CVE-2026-40989

Updated on 08 May 2026

Severity

5.7 Medium severity

Details

CVSS score
5.7
CVSS vector
CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:H

Overview

About vulnerability

SVG ImageDescription

Under infinite recursion in the routing layer, request-handling can cause OOM error.

SVG ImageAffected Spring Products and Versions

Spring Cloud Function

  • 3.2.x
  • 4.1.x
  • 4.2.x
  • 4.3.x
  • 5.0.x
  • Older, unsupported versions are also affected

SVG ImageMitigation

Users of affected versions should upgrade to the corresponding fixed version.

Affected version(s) Fix version Availability
3.2.x 3.2.16 Enterprise Support Only
4.1.x 4.1.10 Enterprise Support Only
4.2.x 4.2.6 Enterprise Support Only
4.3.x 4.3.3 OSS
5.0.x 5.0.2 OSS

If you are not able to upgrade, ensure functions can not be composed with itself

SVG ImageReferences

Details

SVG ImageDescription

Under infinite recursion in the routing layer, request-handling can cause OOM error.

SVG ImageAffected Spring Products and Versions

Spring Cloud Function

  • 3.2.x
  • 4.1.x
  • 4.2.x
  • 4.3.x
  • 5.0.x
  • Older, unsupported versions are also affected

SVG ImageMitigation

Users of affected versions should upgrade to the corresponding fixed version.

Affected version(s) Fix version Availability
3.2.x 3.2.16 Enterprise Support Only
4.1.x 4.1.10 Enterprise Support Only
4.2.x 4.2.6 Enterprise Support Only
4.3.x 4.3.3 OSS
5.0.x 5.0.2 OSS

If you are not able to upgrade, ensure functions can not be composed with itself

SVG ImageReferences