Executive brief
Spring Cloud Stream is a framework for building event-driven microservices that process messages from brokers. This vulnerability allows an attacker to exploit unsafe deserialization to execute arbitrary code on systems using affected versions. An attacker with network access to the message broker could inject malicious serialized objects, leading to remote code execution and complete system compromise.
Technical details
The vulnerability involves unsafe deserialization of untrusted Java objects within Spring Cloud Stream's message processing pipeline. The root cause is insufficient validation of serialized types before deserialization, allowing an attacker to instantiate arbitrary classes. An attacker with access to the underlying message broker (RabbitMQ, Kafka, etc.) can craft malicious serialized payloads that, when deserialized by the application, execute arbitrary code. The attack vector is network-adjacent, requiring broker access. Patches are available in Spring Cloud Stream 4.2.7+, 4.3.4+, and 5.0.3+.
Affected products
- Spring Cloud Stream 4.2.0–4.2.6, 4.3.0–4.3.3, 5.0.0–5.0.2
Timeline
- 2026-08-27: disclosed