Use of cache containing sensitive information in Spring Cloud Stream - CVE-2026-59304

 

Use of cache containing sensitive information in Spring Cloud Stream - CVE-2026-59304

Published: August 31, 2026


Vulnerability identifier: #VU146429
CSH Severity: Low
CVSS v4: 1.8 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-59304
CWE-ID: CWE-524
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose limited sensitive information and modify limited data.

The vulnerability exists due to improper caching of the original content type in Spring Cloud Stream Avro when processing avro content. A remote privileged user can use specially crafted content handling conditions to disclose limited sensitive information and modify limited data.

User interaction is required.


Affected software

Spring Cloud Stream

How to mitigate CVE-2026-59304

Install security update from vendor's website.

Spring Cloud Stream - addressed in versions 4.2.7, 4.3.4, 5.0.3

External References

Related Security Bulletins