Deserialization Vulnerability in Spring Framework Products by VMware
CVE-2026-41855
8.1HIGH
What is CVE-2026-41855?
The Spring Framework contains a vulnerability where the MappingJackson2MessageConverter and JacksonJsonMessageConverter components allow malicious actors to instantiate arbitrary classes in an untrusted Java Message Service (JMS) environment. This weakness can enable unauthorized actions through gadget class deserialization, thereby posing significant security risks to applications utilizing these Spring components.
Affected Version(s)
Spring Framework 7.0.0 < 7.0.7.1
Spring Framework 6.2.0 < 6.2.18.1
Spring Framework 6.1.0 < 6.1.28
