Improper Partition Interceptor in Spring Cloud Stream by Pivotal Software
CVE-2026-59305

3.1LOW

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59305?

An issue has been identified in Spring Cloud Stream where the partition interceptor can be improperly added during message transmission. This could potentially lead to unintended message routing and processing behaviors, impacting the expected functionality of the system. Users are advised to review the versions in use and apply necessary updates or patches to mitigate this vulnerability.

Affected Version(s)

Spring Cloud Stream 5.0.0 <= 5.0.2

Spring Cloud Stream 4.3.0 <= 4.3.3

Spring Cloud Stream 4.2.0 <= 4.2.6

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.