SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-59306

LOW · CVSS 3.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

Spring Cloud Stream versions 4.2.0 to 5.0.2 are vulnerable to deserialization of untrusted types, which could allow an attacker to execute arbitrary code if they can manipulate the input data. Although the severity is rated low, organizations using these specific versions should prioritize patching to mitigate potential exploitation risks, especially if they handle sensitive data or are exposed to untrusted sources.

CVE
CVE-2026-59306
Severity
LOW
CVSS
3.1
EPSS
0.23%

Original NVD Description

Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

Related CVEs

Other vulnerabilities affecting the same vendor(s)