CVE-2026-59324
- EPSS 0.24%
- Veröffentlicht 27.08.2026 18:04:51
- Zuletzt bearbeitet 01.09.2026 23:36:07
When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, a...
CVE-2026-59322
- EPSS 0.21%
- Veröffentlicht 27.08.2026 18:04:50
- Zuletzt bearbeitet 01.09.2026 23:39:47
The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain Map and constructs a GenericMessa...
CVE-2026-59321
- EPSS 0.12%
- Veröffentlicht 27.08.2026 18:04:49
- Zuletzt bearbeitet 31.08.2026 17:27:25
A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report THREADING=null (not thread-safe, e.g. the Kotlin kts engine), concurrent message processing can corrupt engine-internal state, pote...
CVE-2026-59311
- EPSS 0.34%
- Veröffentlicht 27.08.2026 18:04:40
- Zuletzt bearbeitet 31.08.2026 18:06:13
A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts. Spring Integration 7.1.0 Spring Integration 7....
- EPSS 0.35%
- Veröffentlicht 27.08.2026 17:58:02
- Zuletzt bearbeitet 31.08.2026 18:09:32
An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is a Spring-managed bean. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5...
CVE-2026-59293
- EPSS 0.22%
- Veröffentlicht 27.08.2026 17:57:51
- Zuletzt bearbeitet 31.08.2026 23:14:00
Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM. Spring Integration 7.1.0 Spring Integratio...
CVE-2026-59292
- EPSS 0.14%
- Veröffentlicht 27.08.2026 17:57:50
- Zuletzt bearbeitet 31.08.2026 23:07:56
PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdir}/spring-integration/metadata-store.properties with world-readable permissions. Spring Integration 7.1.0 Spring Integration 7.0.0...
CVE-2026-59274
- EPSS 0.24%
- Veröffentlicht 27.08.2026 06:17:21
- Zuletzt bearbeitet 01.09.2026 18:27:09
The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denial-of-service outage. Spring Integration 7.1.0 Sprin...
CVE-2026-47880
- EPSS 0.18%
- Veröffentlicht 27.08.2026 06:17:17
- Zuletzt bearbeitet 10.09.2026 15:08:04
A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into the Spring Integration MessageHe...
CVE-2026-47864
- EPSS 3.44%
- Veröffentlicht 27.08.2026 06:17:17
- Zuletzt bearbeitet 02.09.2026 15:40:07
SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body resolves to a Serializable type...