CRITICAL9.8CVE-2022-22963⚠ KEVSpring Cloud Function Code Injection with a specially crafted SpEL as a routing expression
>= 3.2.0, < 3.2.3
HIGH8.2CVE-2024-22271Spring Cloud Function Framework vulnerable to Denial of Service
>= 4.0.0, < 4.0.8
MEDIUM5.7CVE-2026-40990Spring Cloud Function Context: Uncontrolled Recursion is possible while attempting to add infinite amount of functions to Function Registry
>= 4.3.0, < 4.3.3
MEDIUM5.7Spring Cloud Function Context has Uncontrolled Recursion