Input validation error in Spring Integration - CVE-2026-47856
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information, modify data, or cause a denial of service.
The vulnerability exists due to improper input validation in JsonToObjectTransformer when processing externally supplied json__TypeId__ message headers during JSON to object conversion. A remote user can supply a crafted header value to disclose sensitive information, modify data, or cause a denial of service.
The issue occurs when the header originates from an external producer and is mapped from the inbound transport into the message.
Affected software
Library Support for Spring
How to mitigate CVE-2026-47856
Library Support for Spring - update to 3.5.19