Spring / Spring Integration
16 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-59324 | fluxTransform shared RequestMessageHolder causes cross-message header leakage under async fluxFunction | HIGH | 8.2 | Aug 27, 2026 |
| CVE-2026-59322 | EmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeaders | MEDIUM | 6.3 | Aug 27, 2026 |
| CVE-2026-59321 | Shared JSR-223 ScriptEngine evaluated concurrently without THREADING check | MEDIUM | 5.4 | Aug 27, 2026 |
| CVE-2026-59311 | Fixed predictable /tmp/ziptransformer work directory enables symlink pre-creation | MEDIUM | 6.8 | Aug 27, 2026 |
| CVE-2026-59307 | Deserialization allow-list silently bypassed: setBeanClassLoader replaces deserializer but mapper keeps stale reference | HIGH | 8.0 | Aug 27, 2026 |
| CVE-2026-59293 | SMB minimum protocol dialect defaults to SMB1 | MEDIUM | 6.6 | Aug 27, 2026 |
| CVE-2026-59292 | World-readable metadata file in PropertiesPersistingMetadataStore (insecure temp-file permissions) | LOW | 3.2 | Aug 27, 2026 |
| CVE-2026-59274 | Unbounded decompression in UnZipTransformer enables zip-bomb DoS | MEDIUM | 6.5 | Aug 27, 2026 |
| CVE-2026-47880 | DefaultJmsHeaderMapper copies all JMS user properties into MessageHeaders without excluding framework-significant names | MEDIUM | 5.4 | Aug 27, 2026 |
| CVE-2026-47864 | Unsafe Java deserialization in SerializingHttpMessageConverter — remote code execution | CRITICAL | 9.8 | Aug 27, 2026 |
| CVE-2026-47861 | UDP adapter sends ack to attacker-supplied host:port parsed from packet body, even when acknowledge=false | MEDIUM | 6.3 | Aug 26, 2026 |
| CVE-2026-47862 | ZipTransformer uses file_name header to build workDirectory path without sanitization | MEDIUM | 5.4 | Aug 26, 2026 |
| CVE-2026-47859 | Unbounded memory allocation in RFC6587SyslogDeserializer (octet-counted framing) — remote DoS | MEDIUM | 6.5 | Aug 26, 2026 |
| CVE-2026-47856 | JsonToObjectTransformer resolves the json__TypeId__ message header to an arbitrary class without an allow-list | MEDIUM | 6.3 | Aug 26, 2026 |
| CVE-2026-40987 | Remote-file synchronizer in Spring Integration writes server-supplied filename under localDirectory without canonicalization | HIGH | 7.1 | Jun 11, 2026 |
| CVE-2019-3772 | Spring Integration XML External Entity Injection (XXE) | CRITICAL | 9.8 | Jan 18, 2019 |
Showing 1 to 16 of 16 CVEs