Input validation error in Spring Integration - CVE-2026-47880

 

Input validation error in Spring Integration - CVE-2026-47880

Published: August 28, 2026


Vulnerability identifier: #VU146201
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-47880
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to redirect handler output or error messages and disclose sensitive information.

The vulnerability exists due to improper input validation in DefaultJmsHeaderMapper and downstream channel resolution when processing JMS messages with user-controlled properties. A remote user can set crafted JMS properties named replyChannel, errorChannel, or json__TypeId__ to redirect handler output or error messages and disclose sensitive information.

The issue affects Spring Integration JMS inbound components that consume messages from a JMS destination.


Affected software

Spring Integration
Library Support for Spring

How to mitigate CVE-2026-47880

Install security update from vendor's website.

Spring Integration - addressed in versions 5.5.22, 6.4.13, 6.5.11, 7.0.5.1, 7.0.6, 7.1.0.1, 7.1.1
Library Support for Spring - update to 3.5.19

External References

Related Security Bulletins