{"id":"CVE-2026-59302","title":"Potential for logging sensitive data in Spring Cloud Stream.\nSpring Cloud Stream 5.0.0 - 5.0.2\nSpring Cloud Stream 4.3.0 - 4.3.3\nSpring Cloud Stream 4.2.0 - 4.2.6","summary":"Potential for logging sensitive data in Spring Cloud Stream.\nSpring Cloud Stream 5.0.0 - 5.0.2\nSpring Cloud Stream 4.3.0 - 4.3.3\nSpring Cloud Stream 4.2.0 - 4.2.6","severity":"low","cvss":3.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-532"],"vendor":"vmware","product":"spring_cloud_function","affected":["spring_cloud_function >= 4.2.0, < 4.2.7","spring_cloud_function >= 4.3.0, < 4.3.4","spring_cloud_function >= 5.0.0, < 5.0.3"],"patched":["spring_cloud_function 5.0.3"],"published":"2026-08-27","updated":"2026-09-23","sourceUpdated":"2026-09-23T16:17:44.607","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59302","references":[{"url":"https://spring.io/security/cve-2026-59302","label":"security@vmware.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59302.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-59302"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59302"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.0015,"epssPercentile":0.04567,"scores":{"nvd":3.1,"vendor":3.3},"ingestedAt":"2026-08-29T21:42:35.646Z","slug":"CVE-2026-59302","body":"## Overview\n\nPotential for logging sensitive data in Spring Cloud Stream.\nSpring Cloud Stream 5.0.0 - 5.0.2\nSpring Cloud Stream 4.3.0 - 4.3.3\nSpring Cloud Stream 4.2.0 - 4.2.6\n\n## Affected\n\n- `spring_cloud_function >= 4.2.0, < 4.2.7`\n- `spring_cloud_function >= 4.3.0, < 4.3.4`\n- `spring_cloud_function >= 5.0.0, < 5.0.3`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `spring_cloud_function 5.0.3`\n\n## Vendor advisories\n\n- **Red Hat VEX** · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59302.json)","depth":"sunlit","depthScore":17,"depthScoreParts":{"impact":17.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}