Vulnerability Details CVE-2026-40990
OOM error is possible while attempting to add infinite amount of functions to Function Registry.
Affected Spring Products and Versions:
Spring Cloud Function 3.2.x: versions prior to 3.2.16
Spring Cloud Function 4.1.x: versions prior to 4.1.10
Spring Cloud Function 4.2.x: versions prior to 4.2.6
Spring Cloud Function 4.3.x: versions prior to 4.3.3
Spring Cloud Function 5.0.x: versions prior to 5.0.2
Older, unsupported versions are also affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 4.6%
CVSS Severity
CVSS v3 Score 5.7
Products affected by CVE-2026-40990
-
cpe:2.3:a:vmware:spring_cloud_function:3.2.0
-
cpe:2.3:a:vmware:spring_cloud_function:3.2.1
-
cpe:2.3:a:vmware:spring_cloud_function:3.2.2
-
cpe:2.3:a:vmware:spring_cloud_function:3.2.3
-
cpe:2.3:a:vmware:spring_cloud_function:3.2.4
-
cpe:2.3:a:vmware:spring_cloud_function:3.2.5
-
cpe:2.3:a:vmware:spring_cloud_function:3.2.6
-
cpe:2.3:a:vmware:spring_cloud_function:4.1.0
-
cpe:2.3:a:vmware:spring_cloud_function:4.1.1
-
cpe:2.3:a:vmware:spring_cloud_function:4.1.2
-
cpe:2.3:a:vmware:spring_cloud_function:4.1.3
-
cpe:2.3:a:vmware:spring_cloud_function:4.1.4
-
cpe:2.3:a:vmware:spring_cloud_function:4.1.5
-
cpe:2.3:a:vmware:spring_cloud_function:4.1.6
-
cpe:2.3:a:vmware:spring_cloud_function:4.2.0
-
cpe:2.3:a:vmware:spring_cloud_function:4.2.1
-
cpe:2.3:a:vmware:spring_cloud_function:4.2.2
-
cpe:2.3:a:vmware:spring_cloud_function:4.2.3
-
cpe:2.3:a:vmware:spring_cloud_function:4.2.4
-
cpe:2.3:a:vmware:spring_cloud_function:4.3.0
-
cpe:2.3:a:vmware:spring_cloud_function:4.3.1
-
cpe:2.3:a:vmware:spring_cloud_function:4.3.2
-
cpe:2.3:a:vmware:spring_cloud_function:5.0.0
-
cpe:2.3:a:vmware:spring_cloud_function:5.0.1