CVE-2026-59303: Dynamic destination cache size is not properly bound in Spring Cloud Stream
Published Aug 27, 2026
·Updated
Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6
Affected Software
1 affected component
VMware Spring Cloud Stream>=5.0.0<=5.0.2, >=4.3.0<=4.3.3, >=4.2.0<=4.2.6
Event History
Aug 27, 2026
CVE Published
via MITRE·05:57 PM
Data Sourced
via MITRE·05:57 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverity
Frequently Asked Questions
1
Which Spring Cloud Stream releases should teams review?
Review deployments using Spring Cloud Stream 5.0.0 through 5.0.2, 4.3.0 through 4.3.3, or 4.2.0 through 4.2.6.
2
What would an attacker need to exploit this issue?
The CVSS vector indicates network reachability, high attack complexity, high privileges, and user interaction are required. The issue has low confidentiality and integrity impact and no listed availability impact.