Exposure of Resource to Wrong Sphere in Spring Integration - CVE-2026-59324
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and misroute replies.
The vulnerability exists due to improper state management in RequestMessageHolder used by fluxTransform() on FluxMessageChannel subscriptions when processing concurrent requests with an asynchronous or reordering fluxFunction that emits raw payloads. A remote attacker can send concurrent requests to disclose sensitive information and misroute replies.
The issue occurs when reply headers such as replyChannel, errorChannel, correlationId, or propagated security and tenant headers are copied from the most recently consumed upstream message.
Affected software
Library Support for Spring
How to mitigate CVE-2026-59324
Library Support for Spring - update to 3.5.19