CVE-2026-59304: Improper caching of the original content type in Spring Cloud Stream Avro
Published Aug 27, 2026
·Updated
Improper caching of the original content type in Spring Cloud Stream Avro. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6
Affected Software
3 affected components
Pivotal Software Spring Cloud Stream Avro>=5.0.0<=5.0.2
Pivotal Software Spring Cloud Stream Avro>=4.3.0<=4.3.3
Pivotal Software Spring Cloud Stream Avro>=4.2.0<=4.2.6
Event History
Aug 27, 2026
CVE Published
via MITRE·05:58 PM
Data Sourced
via MITRE·05:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverity
Frequently Asked Questions
1
Which Spring Cloud Stream versions are affected?
Affected versions are Spring Cloud Stream 5.0.0 through 5.0.2, 4.3.0 through 4.3.3, and 4.2.0 through 4.2.6.
2
What level of access and interaction does exploitation require?
The supplied CVSS vector indicates exploitation is network-reachable but has high attack complexity, requires high privileges, and requires user interaction. The potential impact is limited to low confidentiality and integrity impact, with no availability impact.