CVE-2026-59307
8
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Summary
An operator who calls JdbcMessageStore.addAllowedPatterns(…) to restrict deserialization receives no protection at all when the store is a Spring-managed bean. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Integration | 7.1.0 | affected |
| Spring | Spring Integration | 7.0.0 <= 7.0.5 | affected |
| Spring | Spring Integration | 6.5.0 <= 6.5.10 | affected |
| Spring | Spring Integration | 6.4.0 <= 6.4.12 | affected |
Weaknesses
- CWE-502 Deserialization of Untrusted Data
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.