← Browse

CVE-2026-40990

Low

No strong exploitation signal.

CVSS base
5.7 MEDIUM
CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:H
EPSS — probability of exploitation (30 days)
0.2%
11.8th percentile
CISA KEV
Not listed
Weakness / dates
CWE-770
Published 2026-06-01 · modified 2026-07-22

CVSS breakdown

CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:H

Attack VectorPPhysical
Attack ComplexityLLow
Privileges RequiredLLow
User InteractionRRequired
ScopeCChanged
ConfidentialityNNone
IntegrityLLow
AvailabilityHHigh

Timeline

Description

OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions prior to 3.2.16 Spring Cloud Function 4.1.x: versions prior to 4.1.10 Spring Cloud Function 4.2.x: versions prior to 4.2.6 Spring Cloud Function 4.3.x: versions prior to 4.3.3 Spring Cloud Function 5.0.x: versions prior to 5.0.2 Older, unsupported versions are also affected.

Affected

vmware

References

Official: NVD · CVE.org