Sensitive Data Logging Issue in Spring Cloud Stream by Pivotal
CVE-2026-59302

3.1LOW

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59302?

A vulnerability exists in Spring Cloud Stream that may allow sensitive data to be logged unintentionally. This issue affects specific versions ranging from 4.2.0 to 5.0.2, potentially exposing critical information to unauthorized parties. Implementing recommended security practices and updates is vital to mitigate this risk and protect sensitive data.

Affected Version(s)

Spring Cloud Stream 5.0.0 <= 5.0.2

Spring Cloud Stream 4.3.0 <= 4.3.3

Spring Cloud Stream 4.2.0 <= 4.2.6

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.