Inclusion of Sensitive Information in Log Files in Spring Cloud Stream - CVE-2026-59302

 

Inclusion of Sensitive Information in Log Files in Spring Cloud Stream - CVE-2026-59302

Published: August 31, 2026


Vulnerability identifier: #VU146427
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59302
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to improper handling of sensitive information in logging functionality in Spring Cloud Stream when processing application data that is written to logs. A remote privileged user can trigger logging of sensitive data to disclose sensitive information.

User interaction is required.


Affected software

Spring Cloud Stream

How to mitigate CVE-2026-59302

Install security update from vendor's website.

Spring Cloud Stream - addressed in versions 4.2.7, 4.3.4, 5.0.3

External References

Related Security Bulletins