CVE-2026-59304
published 2026-08-27CVE-2026-59304: Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud…
PriorityP413low3.8CVSS 3.1
AVNACLPRHUINSUCLILAN
EPSS
0.15%
4.6th percentile
Improper caching of the original content type in Spring Cloud Stream Avro.
Spring Cloud Stream 5.0.0 - 5.0.2
Spring Cloud Stream 4.3.0 - 4.3.3
Spring Cloud Stream 4.2.0 - 4.2.6
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_cloud_stream | 4.2.0 – 4.2.6 | — |
| spring | spring_cloud_stream | 4.3.0 – 4.3.3 | — |
| spring | spring_cloud_stream | 5.0.0 – 5.0.2 | — |
| vmware | spring_cloud_stream | >= 4.2.0 < 4.2.7 | 4.2.7 |
| vmware | spring_cloud_stream | >= 4.3.0 < 4.3.4 | 4.3.4 |
| vmware | spring_cloud_stream | >= 5.0.0 < 5.0.3 | 5.0.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Improper caching of the original content type in Spring Cloud Stream Avro.
ghsa_unreviewed·2026-08-27
CVE-2026-59304 [LOW] CWE-843 Improper caching of the original content type in Spring Cloud Stream Avro.
Improper caching of the original content type in Spring Cloud Stream Avro.
Spring Cloud Stream 5.0.0 - 5.0.2
Spring Cloud Stream 4.3.0 - 4.3.3
Spring Cloud Stream 4.2.0 - 4.2.6
VulDB
VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 type confusion
vuldb·2026-08-27·CVSS 3.1
CVE-2026-59304 [LOW] VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 type confusion
A vulnerability was found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2. It has been classified as problematic. This affects an unknown part. Performing a manipulation results in type confusion.
This vulnerability is reported as CVE-2026-59304. The attack is possible to be carried out remotely. No exploit exists.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-27
Published