Spring Integration

14 known vulnerabilities in Spring Integration, 1 critical, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-59324 CVSS 8.2 high When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on…
  • CVE-2026-59322 CVSS 6.3 medium The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat…
  • CVE-2026-59321 CVSS 5.4 medium A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report THREADING=null (not…
  • CVE-2026-59311 CVSS 6.8 medium A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by…
  • CVE-2026-59307 CVSS 8.0 high An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is…
  • CVE-2026-59293 CVSS 6.6 medium Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory…
  • CVE-2026-59292 CVSS 3.2 low PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to…
  • CVE-2026-59274 CVSS 6.5 medium The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a…
  • CVE-2026-47880 CVSS 5.4 medium A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties…
  • CVE-2026-47864 CVSS 9.8 critical SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class…
  • CVE-2026-47862 CVSS 5.4 medium An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the…
  • CVE-2026-47861 CVSS 6.3 medium An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to…
  • CVE-2026-47859 CVSS 6.5 medium RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the…
  • CVE-2026-47856 CVSS 6.3 medium Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that…