Back

MEDIUM

Shared JSR-223 ScriptEngine evaluated concurrently without THREADING check

Published Aug 27, 2026

Description

A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report THREADING=null (not thread-safe, e.g. the Kotlin kts engine), concurrent message processing can corrupt engine-internal state, potentially leaking one message's payload/headers bindings into another message's script evaluation or throwing spurious exceptions. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner vmware
Published Aug 27, 2026
Updated Aug 28, 2026
Reserved Jul 4, 2026
CISA Vulnrichment
Updated Aug 28, 2026
NVD
Status Analyzed
Modified Aug 31, 2026
Red Hat
Severity n/a
Public date n/a