CVE-2026-59303
Received Received - Intake

Path Traversal in Spring Cloud Stream

Vulnerability report for CVE-2026-59303, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-27

Last updated on: 2026-08-27

Assigner: VMware

Description

Dynamic destination cache size is not properly bound in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-27
Last Modified
2026-08-27
Generated
2026-08-28
AI Q&A
2026-08-28
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
vmware spring_cloud_stream From 5.0.0 (inc) to 5.0.2 (inc)
vmware spring_cloud_stream From 4.3.0 (inc) to 4.3.3 (inc)
vmware spring_cloud_stream From 4.2.0 (inc) to 4.2.6 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper bounds checking on the dynamic destination cache size in Spring Cloud Stream. It affects specific versions of the software and could allow attackers with high privileges to manipulate cache behavior.

Detection Guidance

Detection involves checking the installed version of Spring Cloud Stream. Use commands like 'find / -name spring-cloud-stream-*.jar' to locate the library and verify its version against the affected ranges (4.2.0-4.2.6, 4.3.0-4.3.3, 5.0.0-5.0.2).

Check application logs for cache-related errors or unusual memory usage patterns that may indicate unbounded cache growth.

Impact Analysis

The impact is limited due to the need for high privileges to exploit. It may lead to minor confidentiality and integrity issues, such as unauthorized data access or modification, but the overall risk is low.

Mitigation Strategies

Upgrade to fixed versions: 5.0.3 (OSS), 4.3.4 (Enterprise Support), or 4.2.7 (Enterprise Support Only). No additional mitigation steps are required beyond upgrading.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-59303. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart