Improper Bound Check in Spring Cloud Stream Affects Multiple Versions
CVE-2026-59303

3.1LOW

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59303?

A vulnerability exists in Spring Cloud Stream due to improper bounding of the dynamic destination cache size. This weakness can lead to unexpected behavior, potentially allowing attackers to manipulate cache management processes within applications. The affected versions include Spring Cloud Stream from 4.2.0 to 5.0.2. Users are encouraged to update their installations to mitigate risks associated with this vulnerability.

Affected Version(s)

Spring Cloud Stream 5.0.0 <= 5.0.2

Spring Cloud Stream 4.3.0 <= 4.3.3

Spring Cloud Stream 4.2.0 <= 4.2.6

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.