CVE-2026-47861
- EPSS 0.25%
- Veröffentlicht 26.08.2026 23:49:25
- Zuletzt bearbeitet 02.09.2026 16:28:35
An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing. Sprin...
CVE-2026-47862
- EPSS 0.25%
- Veröffentlicht 26.08.2026 23:28:47
- Zuletzt bearbeitet 02.09.2026 16:26:14
An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory. Spring ...
CVE-2026-47859
- EPSS 0.2%
- Veröffentlicht 26.08.2026 23:28:45
- Zuletzt bearbeitet 04.09.2026 20:12:57
RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an octet-counted frame and allocates a byte array of exactly that size with no upper ...
CVE-2026-47856
- EPSS 0.24%
- Veröffentlicht 26.08.2026 23:28:43
- Zuletzt bearbeitet 04.09.2026 20:09:41
Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list. Spring Integration 7.1.0 Spring...
CVE-2026-40987
- EPSS 0.21%
- Veröffentlicht 11.06.2026 05:03:32
- Zuletzt bearbeitet 04.09.2026 18:07:41
A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration 7.0.0 through 7.0.4; 6.5.0 th...
CVE-2020-5413
- EPSS 4.41%
- Veröffentlicht 31.07.2020 20:15:13
- Zuletzt bearbeitet 21.11.2024 05:34:07
Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to the "deserialization gadgets" ...
CVE-2019-3772
- EPSS 3%
- Veröffentlicht 18.01.2019 22:29:00
- Zuletzt bearbeitet 21.11.2024 04:42:29
Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.