CVE-2026-59326
Last modified
CVE-2026-59326 is a low-severity vulnerability rated 3.3/10 on the CVSS scale. The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form http://user:pass@proxy:8080, and the language server writes this value to its log file without any redaction. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form http://user:pass@proxy:8080, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Broadcom | Spring Tools | < 2.3.0 |
| Broadcom | Spring Tools | < 5.3.0 |
References
- https://spring.io/security/cve-2026-59326Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-59326?
How severe is CVE-2026-59326?
How do I fix CVE-2026-59326?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59319RedisChatMemoryRepository.findByMetadata() builds RediSearch…4.3
- CVE-2026-59320When a container-level ErrorHandler is configured (the mitig…6.5
- CVE-2026-59321A single ScriptEngine instance is reused for every message o…5.4
- CVE-2026-59322The EmbeddedHeadersJsonMessageMapper defaults to an overly p…6.3
- CVE-2026-59323An application using Micrometer Tracing with W3C baggage pro…5.3
- CVE-2026-59324When an IntegrationFlow uses .fluxTransform() with an asynch…8.2
- CVE-2026-59327Spring Tools for Eclipse stores the Spring Boot DevTools rem…4.4
- CVE-2026-59328Spring Tools for Eclipse renders Spring Boot starter wizard …4.2
- CVE-2026-59335Improper handling of case sensitivity (CWE-178) in the ident…8.7
- CVE-2026-5934The WP Rocket plugin for WordPress is vulnerable to Stored C…7.2
- CVE-2026-59341A security vulnerability exists in the Sealed Secrets contro…4.2
- CVE-2026-5935IBM Total Storage Service Console (TSSC) / TS4500 IMC 9.2, 9…9.8
Are you affected by CVE-2026-59326?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
