Deserialization Vulnerability in Spring Cloud Stream by VMware
CVE-2026-59306
3.1LOW
What is CVE-2026-59306?
A vulnerability exists in Spring Cloud Stream that enables the deserialization of untrusted types. This flaw can be exploited to compromise the application’s security, potentially allowing attackers to execute arbitrary code or cause unintended behavior. Users are encouraged to update to the latest versions of the Spring Cloud Stream to mitigate risks associated with this vulnerability.
Affected Version(s)
Spring Cloud Stream 5.0.0 <= 5.0.2
Spring Cloud Stream 4.3.0 <= 4.3.3
Spring Cloud Stream 4.2.0 <= 4.2.6
