Deserialization Vulnerability in Spring Framework Products by VMware
CVE-2026-41855

8.1HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41855?

The Spring Framework contains a vulnerability where the MappingJackson2MessageConverter and JacksonJsonMessageConverter components allow malicious actors to instantiate arbitrary classes in an untrusted Java Message Service (JMS) environment. This weakness can enable unauthorized actions through gadget class deserialization, thereby posing significant security risks to applications utilizing these Spring components.

Affected Version(s)

Spring Framework 7.0.0 < 7.0.7.1

Spring Framework 6.2.0 < 6.2.18.1

Spring Framework 6.1.0 < 6.1.28

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.