Intel

AIKIDO-2026-780561

spring-cloud-function-adapter-aws is vulnerable to Insertion of Sensitive Information into Log File

Insertion of Sensitive Information into Log FileCVE-2026-59300 Published 5 days ago

31

Low Risk

This Affects:

JAVAspring-cloud-function-adapter-aws
0.0.1 - 5.0.3
Fixed in 5.0.4
Are you affected? Scan for Free

TL;DR

spring-cloud-function-adapter-aws can write sensitive data to logs. Secrets or payload fields may then appear in CloudWatch or application logs. Anyone with log access can recover that material. The patch redacts sensitive values before logging.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and the AWS adapter logs request or credential material.

Background info

spring-cloud-function-adapter-aws is vulnerable to Insertion of Sensitive Information into Log File in versions 0.0.1 - 5.0.3.

How to fix this

Upgrade the org.springframework.cloud:spring-cloud-function-adapter-aws library to the patch version.