CVE-2026-59303
published 2026-08-27CVE-2026-59303: Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud…
PriorityP413low3.8CVSS 3.1
AVNACLPRHUINSUCLILAN
EPSS
0.15%
4.6th percentile
Dynamic destination cache size is not properly bound in Spring Cloud Stream.
Spring Cloud Stream 5.0.0 - 5.0.2
Spring Cloud Stream 4.3.0 - 4.3.3
Spring Cloud Stream 4.2.0 - 4.2.6
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_cloud_stream | 4.2.0 – 4.2.6 | — |
| spring | spring_cloud_stream | 4.3.0 – 4.3.3 | — |
| spring | spring_cloud_stream | 5.0.0 – 5.0.2 | — |
| vmware | spring_cloud_stream | >= 4.2.0 < 4.2.7 | 4.2.7 |
| vmware | spring_cloud_stream | >= 4.3.0 < 4.3.4 | 4.3.4 |
| vmware | spring_cloud_stream | >= 5.0.0 < 5.0.3 | 5.0.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 allocation of resources
vuldb·2026-08-27·CVSS 3.1
CVE-2026-59303 [LOW] VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 allocation of resources
A vulnerability was found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 and classified as problematic. Affected by this issue is some unknown functionality. Such manipulation leads to allocation of resources.
This vulnerability is documented as CVE-2026-59303. The attack can be executed remotely. There is not any exploit available.
GHSA
Dynamic destination cache size is not properly bound in Spring Cloud Stream.
ghsa_unreviewed·2026-08-27
CVE-2026-59303 [LOW] CWE-770 Dynamic destination cache size is not properly bound in Spring Cloud Stream.
Dynamic destination cache size is not properly bound in Spring Cloud Stream.
Spring Cloud Stream 5.0.0 - 5.0.2
Spring Cloud Stream 4.3.0 - 4.3.3
Spring Cloud Stream 4.2.0 - 4.2.6
No detection rules found.
No public exploits indexed.
2026-08-27
Published