Input validation error in Spring Integration - CVE-2026-47856

 

Input validation error in Spring Integration - CVE-2026-47856

Published: August 28, 2026


Vulnerability identifier: #VU146196
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47856
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information, modify data, or cause a denial of service.

The vulnerability exists due to improper input validation in JsonToObjectTransformer when processing externally supplied json__TypeId__ message headers during JSON to object conversion. A remote user can supply a crafted header value to disclose sensitive information, modify data, or cause a denial of service.

The issue occurs when the header originates from an external producer and is mapped from the inbound transport into the message.


Affected software

Spring Integration
Library Support for Spring

How to mitigate CVE-2026-47856

Install security update from vendor's website.

Spring Integration - addressed in versions 5.5.22, 6.4.13, 6.5.11, 7.0.5.1, 7.0.6, 7.1.0.1, 7.1.1
Library Support for Spring - update to 3.5.19

External References

Related Security Bulletins