CVE-2026-59326

Source
https://cve.org/CVERecord?id=CVE-2026-59326
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59326.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-59326
Published
2026-07-30T05:34:08Z
Modified
2026-09-10T11:45:42Z
Severity
  • 3.3 (Low) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
HTTP Proxy Credentials Logged in Plaintext by the Spring Boot Language Server
Details

The Spring Boot language server logs the raw value of the https_proxy/HTTPS_PROXY/http_proxy/HTTP_PROXY environment variable at INFO level whenever it creates an outbound HTTP client and no explicit http.proxy workspace setting is configured. Corporate proxy URLs frequently embed Basic-auth credentials in the form http://user:pass@proxy:8080, and the language server writes this value to its log file without any redaction. Since language server log files are often attached to bug reports or are readable by other local users/processes, this can result in disclosure of proxy credentials. Affected Spring Products and Versions: Spring Tools for Eclipse: 5.2.0 and earlier Spring Tools for VSCode / Cursor / Theia: 2.2.0 and earlier

Database specific
{
    "cna_assigner": "vmware",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/59xxx/CVE-2026-59326.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "last_affected": "5.2.0"
                },
                {
                    "last_affected": "2.2.0"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/spring-projects/spring-tools

Affected ranges

Type
GIT
Repo
https://github.com/spring-projects/spring-tools
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:broadcom:spring_tools:*:*:*:*:*:cursor:*:*",
        "cpe:2.3:a:broadcom:spring_tools:*:*:*:*:*:theia:*:*",
        "cpe:2.3:a:broadcom:spring_tools:*:*:*:*:*:visual_studio_code:*:*",
        "cpe:2.3:a:broadcom:spring_tools:*:*:*:*:*:eclipse:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.3.0"
        },
        {
            "fixed": "5.3.0"
        }
    ],
    "source": "CPE_RANGE"
}

Affected versions

3.*
3.9.15.RELEASE
3.9.7.RELEASE
4.*
4.0.0.RELEASE
4.0.1.RELEASE
4.0.2.RELEASE
4.1.1.RELEASE
4.1.2.RELEASE
4.10.0.RELEASE
4.11.0.RELEASE
4.11.1.RELEASE
4.12.0.RELEASE
4.12.1.RELEASE
4.13.0.RELEASE
4.13.1.RELEASE
4.14.0.RELEASE
4.14.1.RELEASE
4.15.0.RELEASE
4.15.2.RELEASE
4.15.3.RELEASE
4.16.0.RELEASE
4.16.1.RELEASE
4.17.0.RELEASE
4.17.1.RELEASE
4.17.2.RELEASE
4.18.0.RELEASE
4.18.1.RELEASE
4.19.0.RELEASE
4.2.0.RELEASE
4.2.1.RELEASE
4.2.2.RELEASE
4.20.0.RELEASE
4.20.1.RELEASE
4.21.0.RELEASE
4.21.1.RELEASE
4.22.0.RELEASE
4.22.1.RELEASE
4.23.0.RELEASE
4.24.0.RELEASE
4.25.0.RELEASE
4.26.0.RELEASE
4.27.0.RELEASE
4.28.0.RELEASE
4.29.0.RELEASE
4.3.0.RELEASE
4.3.1.RELEASE
4.3.2.RELEASE
4.30.0.RELEASE
4.31.0.RELEASE
4.4.1.RELEASE
4.4.2.RELEASE
4.5.0.RELEASE
4.5.1.RELEASE
4.6.0.RELEASE
4.6.1.RELEASE
4.6.2.RELEASE
4.7.0.RELEASE
4.7.1.RELEASE
4.7.2.RELEASE
4.8.0.RELEASE
4.8.1.RELEASE
4.9.0.RELEASE
5.*
5.0.0.RC1
5.0.0.RC2
5.0.0.RELEASE
5.1.0.RELEASE
5.2.0.RELEASE
CF-Manifest-LS-STS-3.*
CF-Manifest-LS-STS-3.9.0.RELEASE
Other
REPO-REORG
REPO-REORG-2020
V_0.*
V_0.0.4-RC.1
V_0.0.5
V_0.0.5-RC.1
V_0.0.5-RC.2
V_0.0.5-RC.3
V_0.0.5-RC.4
V_0.0.5-RC.5
V_0.0.5-RC.6
V_0.0.5-RC.7
V_0.0.6
V_0.0.6-RC.1
V_0.0.7
V_0.0.7-RC.1
V_0.0.8
V_0.0.8-RC.1
V_0.0.9
V_0.0.9-RC.2
V_0.0.9-RC.3
V_0.0.9-RC.4
V_0.1.0
V_0.1.0-RC.1
V_0.1.2
V_0.1.2-RC.1
V_0.1.2-RC.2
V_0.1.2-RC.3
V_0.1.3
V_0.1.3-RC.1
V_0.1.4
V_0.1.4-RC.1
V_0.2.1
V_0.2.1-RC.1
V_0.3.0
V_0.3.0-RC.1
V_0.3.1
V_0.3.1-RC.1
V_0.3.2-RC.1
V_0.4.0
V_0.4.0-RC.1
V_0.5.0
V_0.5.0-RC.1
V_0.5.0-RC.2
V_0.5.0-RC.3
V_0.6.0
V_0.6.0-RC.1
V_0.6.0-RC.2
V_0.6.0-RC.3
V_0.7.0-RC.1
V_1.*
V_1.0.0
V_1.0.0-RC.1
V_1.0.0-RC.2
V_1.0.0-RC.3
V_1.0.0-RC.4
V_1.0.0-RC.5
V_1.0.0-RC.6
V_1.1.0
V_1.1.0-RC.1
V_1.1.0-RC.3
V_1.1.0-RC.4
V_1.1.1
V_1.1.1-RC.1
V_1.1.1-RC.2
V_1.1.1-RC.3
V_1.10.0
V_1.10.0-RC.1
V_1.12.0
V_1.12.0-RC.1
V_1.12.0-RC.2
V_1.12.0-RC.3
V_1.12.0-RC.4
V_1.13.0
V_1.13.0-RC.1
V_1.14.0
V_1.14.0-RC.1
V_1.15.0
V_1.15.0-RC.1
V_1.16.0-RC.1
V_1.16.0-RC.2
V_1.17.0
V_1.17.0-RC.1
V_1.18.0
V_1.18.0-RC.1
V_1.2.0
V_1.2.0-RC.1
V_1.20.0
V_1.20.0-RC.1
V_1.21.0
V_1.21.0-RC.1
V_1.21.0-RC.2
V_1.22.0
V_1.22.0-RC.1
V_1.23.0
V_1.23.0-RC.1
V_1.23.0-RC.2
V_1.24.0
V_1.24.0-RC.1
V_1.25.0
V_1.25.0-RC.1
V_1.25.0-RC.2
V_1.25.1
V_1.25.1-RC.1
V_1.25.1-RC.2
V_1.26.0-RC.2
V_1.27.0
V_1.27.0-RC.1
V_1.28.0
V_1.28.0-RC.1
V_1.29.0
V_1.29.0-RC.1
V_1.29.0-RC.2
V_1.3.0
V_1.3.0-RC.1
V_1.30.0
V_1.30.0-RC.1
V_1.31.0
V_1.31.0-RC.1
V_1.31.0-RC.2
V_1.32.0
V_1.32.0-RC.1
V_1.32.0-RC.2
V_1.33.0
V_1.33.0-RC.2
V_1.34.0
V_1.34.0-RC.1
V_1.35.0
V_1.35.0-RC.1
V_1.36.0-RC.1
V_1.37.0
V_1.37.0-RC.1
V_1.37.0-RC.2
V_1.38.0
V_1.38.0-RC.1
V_1.38.0-RC.3
V_1.39.0
V_1.39.0-RC.1
V_1.4.0
V_1.4.0-RC.1
V_1.40.0
V_1.40.0-RC.1
V_1.41.0
V_1.41.0-RC.1
V_1.41.0-RC.2
V_1.42.0
V_1.42.0-RC.1
V_1.42.0-RC.2
V_1.42.0-RC.3
V_1.42.0-RC.4
V_1.43.0
V_1.43.0-RC.1
V_1.44.0
V_1.44.0-RC.1
V_1.44.0-RC.2
V_1.45.0
V_1.45.0-RC.1
V_1.45.0-RC.2
V_1.45.0-RC.3
V_1.46.0-RC.1
V_1.46.0-RC.2
V_1.47.0
V_1.47.0-RC.1
V_1.49.0
V_1.49.0-RC.1
V_1.49.0-RC.2
V_1.5.0
V_1.5.0-RC.1
V_1.5.0-RC.2
V_1.5.0-RC.3
V_1.50.0
V_1.50.0-RC.1
V_1.50.0-RC.2
V_1.51.0
V_1.51.0-RC.1
V_1.51.0-RC.2
V_1.51.0-RC.3
V_1.52.0
V_1.52.0-RC.1
V_1.53.0
V_1.53.0-RC.1
V_1.53.0-RC.2
V_1.53.0-RC.3
V_1.54.0
V_1.54.0-RC.1
V_1.54.0-RC.2
V_1.55.0
V_1.55.0-RC.1
V_1.6.0
V_1.6.0-RC.1
V_1.7.0
V_1.7.0-RC.1
V_1.7.0-RC.2
V_1.8.0
V_1.8.0-RC.1
V_1.9.0
V_1.9.0-RC.1
V_1.9.0-RC.2
v0.*
v0.0.1
v2.*
v2.2.0
vscode-boot-dev-pack-0.*
vscode-boot-dev-pack-0.2.2
vscode-bosh-1.*
vscode-bosh-1.56.0-M1
vscode-concourse-0.*
vscode-concourse-0.0.1-RELEASE
vscode-concourse-1.*
vscode-concourse-1.56.0-RC1
vscode-manifest-yaml-0.*
vscode-manifest-yaml-0.0.1-RC1
vscode-manifest-yaml-0.0.1-RELEASE
vscode-manifest-yaml-0.0.2-RC1
vscode-manifest-yaml-0.0.2-RELEASE
vscode-spring-boot-1.*
vscode-spring-boot-1.56.0-RC1
vscode-spring-boot-1.56.0-RC2
vscode-spring-boot-1.57.0-RC1
vscode-spring-boot-1.57.0-RC2
vscode-spring-boot-1.57.0-RC3
vscode-spring-boot-1.58.0-RC1
vscode-spring-boot-1.59.0-RC1
vscode-spring-boot-1.59.0-RC2
vscode-spring-boot-1.60.0-RC1
vscode-spring-boot-1.60.0-RC2
vscode-spring-boot-1.61.0-RC1
vscode-spring-boot-1.61.0-RC2
vscode-spring-boot-1.62.0-RC1
vscode-spring-boot-1.63.0-RC1
vscode-spring-boot-1.63.0-RC2
vscode-spring-boot-2.*
vscode-spring-boot-2.0.0-RC2
vscode-spring-boot-2.0.0-RC3
vscode-spring-boot-2.1.0-RC1
vscode-spring-boot-2.1.0-RC2
vscode-spring-boot-2.1.0-RC3
vscode-spring-boot-2.2.0-RC1
vscode-spring-boot-2.3.0-RC1
vscode-spring-cli-0.*
vscode-spring-cli-0.9.0-RC1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-59326.json"