CVE-2026-59274
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Summary
The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denial-of-service outage. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Integration | 7.1.0 | affected |
| Spring | Spring Integration | 7.0.0 <= 7.0.5 | affected |
| Spring | Spring Integration | 6.5.0 <= 6.5.10 | affected |
| Spring | Spring Integration | 6.4.0 <= 6.4.12 | affected |
Weaknesses
- CWE-409 Improper Handling of Highly Compressed Data (Data Amplification, Decompression Bomb)
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.