Impact
Spring Cloud Stream Avro incorrectly caches the original content type of messages, which can cause the framework to interpret data with an unexpected content type. This flaw may lead to incorrect data interpretation, data integrity problems, or unintended processing paths. No official impact such as code execution is cited in the advisory.
Affected Systems
Spring Cloud Stream, versions 5.0.0 through 5.0.2, 4.3.0 through 4.3.3, and 4.2.0 through 4.2.6 are affected.
Risk and Exploitability
The CVSS score is 3.1, indicating low severity. EPSS data is not available and the vulnerability is not listed in CISA KEV, suggesting limited exposure and a low probability of exploitation. The flaw likely requires message traffic to the application, implying the attack vector is internal or remote via the messaging layer. No active exploitation has been reported.
OpenCVE Enrichment