Spring Integration Vulnerability in JMS Inbound Components by Spring
CVE-2026-47880
5.4MEDIUM
What is CVE-2026-47880?
This vulnerability allows a producer to publish messages to a JMS destination that are consumed by any Spring Integration JMS inbound component. Vulnerable components can directly map String JMS properties such as replyChannel, errorChannel, or json__TypeId__ into the Spring Integration MessageHeaders without any validation, potentially compromising the integrity and security of the messaging system.
Affected Version(s)
Spring Integration 7.1.0
Spring Integration 7.0.0 <= 7.0.5
Spring Integration 6.5.0 <= 6.5.10
