Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40990

Опубликовано: 01 июн. 2026
Источник: redhat
CVSS3: 5.5

Описание

OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Function 4.1.x: versions prior to 4.1.10 Spring Cloud Function 4.2.x: versions prior to 4.2.6 Spring Cloud Function 4.3.x: versions prior to 4.3.3 Spring Cloud Function 5.0.x: versions prior to 5.0.2 Older, unsupported versions are also affected.

A flaw was found in Spring Cloud Function. A local attacker with low privileges could exploit this vulnerability by repeatedly adding functions to the Function Registry, leading to an Out Of Memory (OOM) error. This resource exhaustion can cause a Denial of Service (DoS) for the affected application.

Отчет

Red Hat's versions of spring-cloud-function shipped as a transitive dependency in EAP XP predate the affected version range and are not impacted by this vulnerability.

Меры по смягчению последствий

No mitigation is required. The shipped versions do not contain the vulnerable code.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Enterprise Application Platform Expansion Packspring-cloud-function-contextNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2483906spring-cloud-function: Spring Cloud Function: Denial of Service via excessive function registration

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.7
nvd
2 месяца назад

OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Function 4.1.x: versions prior to 4.1.10 Spring Cloud Function 4.2.x: versions prior to 4.2.6 Spring Cloud Function 4.3.x: versions prior to 4.3.3 Spring Cloud Function 5.0.x: versions prior to 5.0.2 Older, unsupported versions are also affected.

CVSS3: 5.7
github
2 месяца назад

Spring Cloud Function Context: Uncontrolled Recursion is possible while attempting to add infinite amount of functions to Function Registry

5.5 Medium

CVSS3