CVE-2026-59305: Partition interceptor may be improperly added while sending message
Published Aug 27, 2026
·Updated
Partition interceptor may be improperly added while sending message. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6
Affected Software
1 affected component
Spring Spring Cloud Stream>=5.0.0<=5.0.2, >=4.3.0<=4.3.3, >=4.2.0<=4.2.6
Event History
Aug 27, 2026
CVE Published
via MITRE·05:58 PM
Data Sourced
via MITRE·05:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverity
Frequently Asked Questions
1
Which Spring Cloud Stream versions are affected?
Affected versions are Spring Cloud Stream 5.0.0 through 5.0.2, 4.3.0 through 4.3.3, and 4.2.0 through 4.2.6.
2
What level of access and interaction does exploitation require?
The severity vector indicates exploitation is network-reachable but has high attack complexity, requires high privileges, and requires user interaction.
3
What impact is indicated if the issue is exploited?
The severity vector indicates low confidentiality and integrity impact, with no availability impact. Scope is unchanged.