Input validation error in Spring Integration - CVE-2026-47861
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to cause the server to send UDP datagrams to arbitrary internal or external hosts and ports.
The vulnerability exists due to improper input validation in the Spring Integration UDP inbound adapter when parsing packet bodies. A remote user can send a crafted UDP packet to cause the server to send UDP datagrams to arbitrary internal or external hosts and ports.
The attacker controls both the destination host and port, and the emitted payload is a 36-byte UUID string.
Affected software
Library Support for Spring
How to mitigate CVE-2026-47861
Library Support for Spring - update to 3.5.19