CVE-2026-47881
- EPSS 0.27%
- Veröffentlicht 27.08.2026 06:17:18
- Zuletzt bearbeitet 01.09.2026 20:21:10
Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for example, a CSV field that contains embedded newlines wrapped in quotes. A specially crafted input file could exploit the way the reader...
CVE-2026-47875
- EPSS 0.25%
- Veröffentlicht 27.08.2026 06:17:17
- Zuletzt bearbeitet 02.09.2026 15:31:14
Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The JobParameterDeserializer does not properly enfo...
CVE-2026-47878
- EPSS 0.25%
- Veröffentlicht 27.08.2026 06:17:17
- Zuletzt bearbeitet 10.09.2026 15:28:35
DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowlist. Spring Ba...
CVE-2020-5411
- EPSS 1.86%
- Veröffentlicht 11.06.2020 17:15:12
- Zuletzt bearbeitet 01.09.2026 18:07:18
When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. Jackson fixed this vulnerability by blacklisting known "deserialization gadgets". Spring Batch configures Jackson...
CVE-2019-3774
- EPSS 3.03%
- Veröffentlicht 18.01.2019 22:29:01
- Zuletzt bearbeitet 01.09.2026 18:07:18
Spring Batch versions 3.0.9, 4.0.1, 4.1.0, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML data from untrusted sources.