Race condition in Spring Integration - CVE-2026-59321
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information or cause a denial of service.
The vulnerability exists due to improper concurrent access in shared JSR-223 ScriptEngine instances in script-backed channels when processing concurrent messages with engines that report THREADING=null. A remote user can trigger concurrent script evaluations to disclose sensitive information or cause a denial of service.
In multi-tenant or request/response flows, one message's payload or header bindings may leak into another message's script evaluation.
Affected software
Library Support for Spring
How to mitigate CVE-2026-59321
Library Support for Spring - update to 3.5.19