Deserialization Vulnerability in Spring Statemachine Products by Spring
CVE-2026-41862
8.8HIGH
What is CVE-2026-41862?
A vulnerability in Spring Statemachine allows for the deserialization of persisted state-machine contexts without enforcing a class allowlist. This oversight potentially exposes applications to remote code execution attacks, specifically through Kryo-based persistence backends such as JPA, MongoDB, Redis, and ZooKeeper. These can lead to serious security breaches if exploited.
Affected Version(s)
Spring Statemachine 4.0.0 < 4.0.1.1
Spring Statemachine 3.2.0 < 3.2.5
