CVE-2026-59326: CWE-532 Insertion of Sensitive Information into Log File in Spring Spring Tools for Eclipse
CVE-2026-59326 is a low-severity vulnerability in Spring Tools for Eclipse (version 5.2.0 and earlier) where the Spring Boot language server logs the raw value of proxy environment variables, including embedded Basic-auth credentials, at INFO level without redaction. This can lead to unintended disclosure of proxy credentials through log files, which may be accessible to other local users or attached to bug reports.
AI Analysis
Technical Summary
The Spring Boot language server component of Spring Tools for Eclipse versions 5.2.0 and earlier logs the raw values of the https_proxy, HTTPS_PROXY, http_proxy, and HTTP_PROXY environment variables at INFO level when creating outbound HTTP clients without an explicit http.proxy workspace setting. Since corporate proxy URLs often embed Basic-auth credentials (e.g., http://user:pass@proxy:8080), these credentials are written to log files without any redaction. Because these log files can be shared or accessed by other local users or processes, this behavior can result in the disclosure of sensitive proxy credentials. The vulnerability is identified as CWE-532 (Insertion of Sensitive Information into Log File).
Potential Impact
The vulnerability can lead to the disclosure of sensitive proxy credentials embedded in environment variables via log files. This exposure is limited to local users or processes with access to the language server log files or to external parties if logs are shared (e.g., attached to bug reports). There is no indication of remote exploitation or impact on integrity or availability. The CVSS score is 3.3 (low severity), reflecting limited confidentiality impact and local attack vector with low privileges required.
Mitigation Recommendations
No official patch or remediation level is currently provided by the vendor. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid embedding sensitive credentials in proxy environment variables or restrict access to language server log files to prevent unauthorized disclosure. Consider configuring explicit http.proxy workspace settings to avoid logging environment variables.
CVE-2026-59326: CWE-532 Insertion of Sensitive Information into Log File in Spring Spring Tools for Eclipse
Description
CVE-2026-59326 is a low-severity vulnerability in Spring Tools for Eclipse (version 5.2.0 and earlier) where the Spring Boot language server logs the raw value of proxy environment variables, including embedded Basic-auth credentials, at INFO level without redaction. This can lead to unintended disclosure of proxy credentials through log files, which may be accessible to other local users or attached to bug reports.
CVSS v3.1
Score 3.3low
Affected software
Spring
Spring Tools for Eclipse
Spring
Spring Tools for VSCode / Cursor / Theia
pkg:maven/org.springframework.boot/spring-tools-eclipseRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Spring Boot language server component of Spring Tools for Eclipse versions 5.2.0 and earlier logs the raw values of the https_proxy, HTTPS_PROXY, http_proxy, and HTTP_PROXY environment variables at INFO level when creating outbound HTTP clients without an explicit http.proxy workspace setting. Since corporate proxy URLs often embed Basic-auth credentials (e.g., http://user:pass@proxy:8080), these credentials are written to log files without any redaction. Because these log files can be shared or accessed by other local users or processes, this behavior can result in the disclosure of sensitive proxy credentials. The vulnerability is identified as CWE-532 (Insertion of Sensitive Information into Log File).
Potential Impact
The vulnerability can lead to the disclosure of sensitive proxy credentials embedded in environment variables via log files. This exposure is limited to local users or processes with access to the language server log files or to external parties if logs are shared (e.g., attached to bug reports). There is no indication of remote exploitation or impact on integrity or availability. The CVSS score is 3.3 (low severity), reflecting limited confidentiality impact and local attack vector with low privileges required.
Mitigation Recommendations
No official patch or remediation level is currently provided by the vendor. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, users should avoid embedding sensitive credentials in proxy environment variables or restrict access to language server log files to prevent unauthorized disclosure. Consider configuring explicit http.proxy workspace settings to avoid logging environment variables.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- vmware
- Date Reserved
- 2026-07-04T18:14:10.167Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a6aee0c9c2644c7f8a7f067
Added to database: 07/30/2026, 06:24:12 UTC
Last enriched: 08/06/2026, 17:58:06 UTC
Last updated: 09/12/2026, 22:01:35 UTC
Views: 62
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.