CVE-2026-59305
published 2026-08-27CVE-2026-59305: Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream…
PriorityP413low3.8CVSS 3.1
AVNACLPRHUINSUCLILAN
EPSS
0.15%
4.6th percentile
Partition interceptor may be improperly added while sending message.
Spring Cloud Stream 5.0.0 - 5.0.2
Spring Cloud Stream 4.3.0 - 4.3.3
Spring Cloud Stream 4.2.0 - 4.2.6
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_cloud_stream | 4.2.0 – 4.2.6 | — |
| spring | spring_cloud_stream | 4.3.0 – 4.3.3 | — |
| spring | spring_cloud_stream | 5.0.0 – 5.0.2 | — |
| vmware | spring_cloud_stream | >= 4.2.0 < 4.2.7 | 4.2.7 |
| vmware | spring_cloud_stream | >= 4.3.0 < 4.3.4 | 4.3.4 |
| vmware | spring_cloud_stream | >= 5.0.0 < 5.0.3 | 5.0.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 Partition Interceptor incorrect behavior order
vuldb·2026-08-27·CVSS 3.1
CVE-2026-59305 [LOW] VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 Partition Interceptor incorrect behavior order
A vulnerability, which was classified as problematic, was found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2. Affected is an unknown function of the component Partition Interceptor. The manipulation results in incorrect behavior order.
This vulnerability is cataloged as CVE-2026-59305. The attack may be launched remotely. There is no exploit available.
GHSA
Partition interceptor may be improperly added while sending message.
ghsa_unreviewed·2026-08-27
CVE-2026-59305 [LOW] CWE-696 Partition interceptor may be improperly added while sending message.
Partition interceptor may be improperly added while sending message.
Spring Cloud Stream 5.0.0 - 5.0.2
Spring Cloud Stream 4.3.0 - 4.3.3
Spring Cloud Stream 4.2.0 - 4.2.6
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-27
Published