CVE-2026-59306
published 2026-08-27CVE-2026-59306: Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud…
PriorityP416low3.8CVSS 3.1
AVNACLPRHUINSUCLILAN
EPSS
0.23%
13.5th percentile
Potential for deserialization of untrusted types in Spring Cloud Stream.
Spring Cloud Stream 5.0.0 - 5.0.2
Spring Cloud Stream 4.3.0 - 4.3.3
Spring Cloud Stream 4.2.0 - 4.2.6
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_cloud_stream | 4.2.0 – 4.2.6 | — |
| spring | spring_cloud_stream | 4.3.0 – 4.3.3 | — |
| spring | spring_cloud_stream | 5.0.0 – 5.0.2 | — |
| vmware | spring_cloud_stream | >= 4.2.0 < 4.2.7 | 4.2.7 |
| vmware | spring_cloud_stream | >= 4.3.0 < 4.3.4 | 4.3.4 |
| vmware | spring_cloud_stream | >= 5.0.0 < 5.0.3 | 5.0.3 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Potential for deserialization of untrusted types in Spring Cloud Stream.
ghsa_unreviewed·2026-08-27
CVE-2026-59306 [LOW] CWE-502 Potential for deserialization of untrusted types in Spring Cloud Stream.
Potential for deserialization of untrusted types in Spring Cloud Stream.
Spring Cloud Stream 5.0.0 - 5.0.2
Spring Cloud Stream 4.3.0 - 4.3.3
Spring Cloud Stream 4.2.0 - 4.2.6
VulDB
VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 deserialization
vuldb·2026-08-27·CVSS 3.1
CVE-2026-59306 [LOW] VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2 deserialization
A vulnerability was found in VMware Spring Cloud Stream up to 4.2.6/4.3.3/5.0.2. It has been declared as problematic. This vulnerability affects unknown code. Executing a manipulation can lead to deserialization.
This vulnerability appears as CVE-2026-59306. The attack may be performed from remote. There is no available exploit.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-27
Published