CVE-2026-59303: Dynamic destination cache size is not properly bound in Spring Cloud Stream
Published Aug 27, 2026
·Updated
Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6
Affected Software
4 affected components
VMware Spring Cloud Stream>=5.0.0<=5.0.2, >=4.3.0<=4.3.3, >=4.2.0<=4.2.6
VMware Spring Cloud Stream>=4.2.0<4.2.7
VMware Spring Cloud Stream>=4.3.0<4.3.4
VMware Spring Cloud Stream>=5.0.0<5.0.3
Remediation
Patch Available
Event History
Aug 27, 2026
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which Spring Cloud Stream releases should teams review?
Review deployments using Spring Cloud Stream 5.0.0 through 5.0.2, 4.3.0 through 4.3.3, or 4.2.0 through 4.2.6.
2
What would an attacker need to exploit this issue?
The CVSS vector indicates network reachability, high attack complexity, high privileges, and user interaction are required. The issue has low confidentiality and integrity impact and no listed availability impact.