Vmware
Vmware Spring Integration: vulnerabilities and CVEs
Vmware Spring Integration has 17 published vulnerabilities, 15 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs17
Last 12 months15
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59324 | High (8.2) | 0.28% | — | Aug 27, 2026 | When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel,… |
| CVE-2026-59322 | Medium (6.3) | 0.29% | — | Aug 27, 2026 | The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain… |
| CVE-2026-59321 | Medium (5.4) | 0.18% | — | Aug 27, 2026 | A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report THREADING=null (not thread-safe, e.g. the Kotlin kts engine), concurrent message processing can… |
| CVE-2026-59311 | Medium (6.8) | 0.39% | — | Aug 27, 2026 | A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating /tmp/ziptransformer as a symlink before the application starts. Spring… |
| CVE-2026-59307 | High (8) | 0.42% | — | Aug 27, 2026 | An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is a Spring-managed bean. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5… |
| CVE-2026-59293 | Medium (6.6) | 0.24% | — | Aug 27, 2026 | Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory signing/encryption and is vulnerable to NTLM relay and content-tampering MITM. Spring… |
| CVE-2026-59292 | Low (3.2) | 0.15% | — | Aug 27, 2026 | PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdir}/spring-integration/metadata-store.properties with world-readable permissions. Spring Integration… |
| CVE-2026-59274 | Medium (6.5) | 0.42% | — | Aug 27, 2026 | The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denial-of-service outage.… |
| CVE-2026-47880 | Medium (5.4) | 0.26% | — | Aug 27, 2026 | A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties named replyChannel, errorChannel, or json__TypeId__ which are copied verbatim into… |
| CVE-2026-47864 | Critical (9.8) | 5.9% | — | Aug 27, 2026 | SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-object whose body… |
| CVE-2026-47862 | Medium (5.4) | 0.30% | — | Aug 27, 2026 | An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the… |
| CVE-2026-47861 | Medium (6.3) | 0.33% | — | Aug 27, 2026 | An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of… |
| CVE-2026-47859 | Medium (6.5) | 0.29% | — | Aug 27, 2026 | RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an octet-counted frame and allocates a byte array of… |
| CVE-2026-47856 | Medium (6.3) | 0.31% | — | Aug 27, 2026 | Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that header value to a class with ClassUtils.forName and no type/package allow-list.… |
| CVE-2026-40987 | High (7.1) | 0.26% | — | Jun 11, 2026 | A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected versions: Spring Integration… |
| CVE-2020-5413 | Critical (9.8) | 4.4% | — | Jul 31, 2020 | Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to… |
| CVE-2019-3772 | Critical (9.8) | 3.0% | — | Jan 18, 2019 | Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported versions, were susceptible to XML External Entity Injection (XXE) when receiving XML… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.