{"id":"CVE-2026-59303","title":"Dynamic destination cache size is not properly bound in Spring Cloud Stream.\nSpring Cloud Stream 5.0.0 - 5.0.2\nSpring Cloud Stream 4.3.0 - 4.3.3\nSpring Cloud Stream 4.2.0 - 4.2.6","summary":"Dynamic destination cache size is not properly bound in Spring Cloud Stream.\nSpring Cloud Stream 5.0.0 - 5.0.2\nSpring Cloud Stream 4.3.0 - 4.3.3\nSpring Cloud Stream 4.2.0 - 4.2.6","severity":"low","cvss":3.1,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N","cwe":["CWE-770"],"published":"2026-08-27","updated":"2026-08-28","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-59303","references":[{"url":"https://spring.io/security/cve-2026-59303","label":"security@vmware.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59303.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-59303"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-59303"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00151,"epssPercentile":0.04652,"ingestedAt":"2026-08-29T21:42:35.686Z","vendor":"Red Hat","slug":"CVE-2026-59303","body":"## Overview\n\nDynamic destination cache size is not properly bound in Spring Cloud Stream.\nSpring Cloud Stream 5.0.0 - 5.0.2\nSpring Cloud Stream 4.3.0 - 4.3.3\nSpring Cloud Stream 4.2.0 - 4.2.6\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-59303.json)","depth":"sunlit","depthScore":17,"depthScoreParts":{"impact":17.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}