Use of cache containing sensitive information in Spring Cloud Stream - CVE-2026-59304
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to disclose limited sensitive information and modify limited data.
The vulnerability exists due to improper caching of the original content type in Spring Cloud Stream Avro when processing avro content. A remote privileged user can use specially crafted content handling conditions to disclose limited sensitive information and modify limited data.
User interaction is required.