CVE-2026-40990

OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Function 4.1.x: versions prior to 4.1.10 Spring Cloud Function 4.2.x: versions prior to 4.2.6 Spring Cloud Function 4.3.x: versions prior to 4.3.3 Spring Cloud Function 5.0.x: versions prior to 5.0.2 Older, unsupported versions are also affected.
References
Link Resource
https://spring.io/security/cve-2026-40990 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_cloud_function:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_cloud_function:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_cloud_function:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_cloud_function:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_cloud_function:*:*:*:*:*:*:*:*

History

05 Jun 2026, 13:47

Type Values Removed Values Added
CPE cpe:2.3:a:vmware:spring_cloud_function:*:*:*:*:*:*:*:*
First Time Vmware
Vmware spring Cloud Function
References () https://spring.io/security/cve-2026-40990 - () https://spring.io/security/cve-2026-40990 - Vendor Advisory

01 Jun 2026, 19:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-01 19:16

Updated : 2026-06-05 13:47


NVD link : CVE-2026-40990

Mitre link : CVE-2026-40990

CVE.ORG link : CVE-2026-40990


JSON object : View

Products Affected

vmware

  • spring_cloud_function
CWE
CWE-770

Allocation of Resources Without Limits or Throttling