Deserialization Vulnerability in Spring Framework by Spring
CVE-2026-59307

8HIGH

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59307?

A vulnerability exists in Spring Integration where operators utilizing the JdbcMessageStore.addAllowedPatterns(...) method to restrict deserialization do not receive any protection when the store operates as a Spring-managed bean. This flaw permits potential exposure to various security risks, allowing attackers to manipulate the deserialization process and potentially compromise application integrity.

Affected Version(s)

Spring Integration 7.1.0

Spring Integration 7.0.0 <= 7.0.5

Spring Integration 6.5.0 <= 6.5.10

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.