Broadcom Spring Statemachine — known CVE vulnerabilities
Every CVE whose affected-product data names Broadcom Spring Statemachine, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (1)
- CVE-2026-41862 — CVSS 8.8 (high): Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts…