Spring Integration Vulnerability in JMS Inbound Components by Spring
CVE-2026-47880

5.4MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-47880?

This vulnerability allows a producer to publish messages to a JMS destination that are consumed by any Spring Integration JMS inbound component. Vulnerable components can directly map String JMS properties such as replyChannel, errorChannel, or json__TypeId__ into the Spring Integration MessageHeaders without any validation, potentially compromising the integrity and security of the messaging system.

Affected Version(s)

Spring Integration 7.1.0

Spring Integration 7.0.0 <= 7.0.5

Spring Integration 6.5.0 <= 6.5.10

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.