cbcvebase.
CVE-2026-59306
published 2026-08-27

CVE-2026-59306: Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud…

PriorityP416low3.8CVSS 3.1
AVNACLPRHUINSUCLILAN
EPSS
0.23%
13.5th percentile
Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

Affected

6 ranges
VendorProductVersion rangeFixed in
springspring_cloud_stream4.2.0 – 4.2.6
springspring_cloud_stream4.3.0 – 4.3.3
springspring_cloud_stream5.0.0 – 5.0.2
vmwarespring_cloud_stream>= 4.2.0 < 4.2.74.2.7
vmwarespring_cloud_stream>= 4.3.0 < 4.3.44.3.4
vmwarespring_cloud_stream>= 5.0.0 < 5.0.35.0.3
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.