Input validation error in Spring Integration - CVE-2026-47880
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to redirect handler output or error messages and disclose sensitive information.
The vulnerability exists due to improper input validation in DefaultJmsHeaderMapper and downstream channel resolution when processing JMS messages with user-controlled properties. A remote user can set crafted JMS properties named replyChannel, errorChannel, or json__TypeId__ to redirect handler output or error messages and disclose sensitive information.
The issue affects Spring Integration JMS inbound components that consume messages from a JMS destination.
Affected software
Library Support for Spring
How to mitigate CVE-2026-47880
Library Support for Spring - update to 3.5.19