CVE-2026-40990
published 2026-06-01CVE-2026-40990: OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud Function…
PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.21%
11.5th percentile
OOM error is possible while attempting to add infinite amount of functions to Function Registry.
Affected Spring Products and Versions:
Spring Cloud Function 3.2.x: versions prior to 3.2.16
Spring Cloud Function 4.1.x: versions prior to 4.1.10
Spring Cloud Function 4.2.x: versions prior to 4.2.6
Spring Cloud Function 4.3.x: versions prior to 4.3.3
Spring Cloud Function 5.0.x: versions prior to 5.0.2
Older, unsupported versions are also affected.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_cloud_function | >= 3.2.0 < 3.2.16 | 3.2.16 |
| spring | spring_cloud_function | >= 4.1.0 < 4.1.10 | 4.1.10 |
| spring | spring_cloud_function | >= 4.2.0 < 4.2.6 | 4.2.6 |
| spring | spring_cloud_function | >= 4.3.0 < 4.3.3 | 4.3.3 |
| spring | spring_cloud_function | >= 5.0.0 < 5.0.2 | 5.0.2 |
| vmware | spring_cloud_function | >= 3.2.0 < 3.2.16 | 3.2.16 |
| vmware | spring_cloud_function | >= 4.1.0 < 4.1.10 | 4.1.10 |
| vmware | spring_cloud_function | >= 4.2.0 < 4.2.6 | 4.2.6 |
| vmware | spring_cloud_function | >= 4.3.0 < 4.3.3 | 4.3.3 |
| vmware | spring_cloud_function | >= 5.0.0 < 5.0.2 | 5.0.2 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Vmware Spring Cloud Function up to 5.0.1 allocation of resources
vuldb·2026-06-01·CVSS 5.7
CVE-2026-40990 [MEDIUM] Vmware Spring Cloud Function up to 5.0.1 allocation of resources
A vulnerability identified as problematic has been detected in Vmware Spring Cloud Function up to 3.2.15/4.1.9/4.2.5/4.3.2/5.0.1. The affected element is an unknown function. This manipulation causes allocation of resources.
This vulnerability is tracked as CVE-2026-40990. It is feasible to perform the attack on the physical device. No exploit exists.
You should upgrade the affected component.
GHSA
Spring Cloud Function Context: Uncontrolled Recursion is possible while attempting to add infinite amount of functions to Function Registry
ghsa·2026-06-01
CVE-2026-40990 [MEDIUM] CWE-770 Spring Cloud Function Context: Uncontrolled Recursion is possible while attempting to add infinite amount of functions to Function Registry
Spring Cloud Function Context: Uncontrolled Recursion is possible while attempting to add infinite amount of functions to Function Registry
OOM error is possible while attempting to add infinite amount of functions to Function Registry.
Affected Spring Products and Versions:
Spring Cloud Function 3.2.x: versions prior to 3.2.16
Spring Cloud Function 4.1.x: versions prior to 4.1.10
Spring Cloud Function 4.2.x: versions prior to 4.2.6
Spring Cloud Function 4.3.x: versions prior to 4.3.3
Spring Cloud Function 5.0.x: versions prior to 5.0.2
Older, unsupported versions are also affected.
GHSA
OOM error is possible while attempting to add infinite amount of functions to Function Registry.
ghsa_unreviewed·2026-06-01
CVE-2026-40990 [MEDIUM] CWE-770 OOM error is possible while attempting to add infinite amount of functions to Function Registry.
OOM error is possible while attempting to add infinite amount of functions to Function Registry.
Affected Spring Products and Versions:
Spring Cloud Function 3.2.x: versions prior to 3.2.16
Spring Cloud Function 4.1.x: versions prior to 4.1.10
Spring Cloud Function 4.2.x: versions prior to 4.2.6
Spring Cloud Function 4.3.x: versions prior to 4.3.3
Spring Cloud Function 5.0.x: versions prior to 5.0.2
Older, unsupported versions are also affected.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-06-01
Published