CVE-2026-59306: VMware Spring Cloud Stream

Low severity, CVSS 3.8. EPSS: 0.2% chance of exploitation in the next 30 days.

Potential for deserialization of untrusted types in Spring Cloud Stream. Spring Cloud Stream 5.0.0 - 5.0.2 Spring Cloud Stream 4.3.0 - 4.3.3 Spring Cloud Stream 4.2.0 - 4.2.6

Affected products

  • VMware Spring Cloud Stream: from 4.2.0, before 4.2.7 (fixed in 4.2.7); from 4.3.0, before 4.3.4 (fixed in 4.3.4); from 5.0.0, before 5.0.3 (fixed in 5.0.3)

Published 2026-08-27. Last modified 2026-09-04.