Input validation error in Spring Integration - CVE-2026-47861

 

Input validation error in Spring Integration - CVE-2026-47861

Published: August 28, 2026


Vulnerability identifier: #VU146198
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47861
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause the server to send UDP datagrams to arbitrary internal or external hosts and ports.

The vulnerability exists due to improper input validation in the Spring Integration UDP inbound adapter when parsing packet bodies. A remote user can send a crafted UDP packet to cause the server to send UDP datagrams to arbitrary internal or external hosts and ports.

The attacker controls both the destination host and port, and the emitted payload is a 36-byte UUID string.


Affected software

Spring Integration
Library Support for Spring

How to mitigate CVE-2026-47861

Install security update from vendor's website.

Spring Integration - addressed in versions 5.5.22, 6.4.13, 6.5.11, 7.0.5.1, 7.0.6, 7.1.0.1, 7.1.1
Library Support for Spring - update to 3.5.19

External References

Related Security Bulletins