Vmware Spring Integration — known CVE vulnerabilities
Every CVE whose affected-product data names Vmware Spring Integration, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (17)
CVE-2019-3772 — CVSS 9.8 (critical): Spring Integration (spring-integration-xml and spring-integration-ws modules), versions 4.3.18, 5.0.10, 5.1.1, and older unsupported…
CVE-2020-5413 — CVSS 9.8 (critical): Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with…
CVE-2026-59324 — CVSS 8.2 (high): When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on…
CVE-2026-59307 — CVSS 8.0 (high): An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when the store is…
CVE-2026-40987 — CVSS 7.1 (high): A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured…
CVE-2026-59311 — CVSS 6.8 (medium): A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing by pre-creating…
CVE-2026-59293 — CVSS 6.6 (medium): Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandatory…
CVE-2026-59274 — CVSS 6.5 (medium): The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a…
CVE-2026-47864 — CVSS 6.4 (medium): SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class…
CVE-2026-47856 — CVSS 6.3 (medium): Spring Integration's JSON to object conversion uses the json__TypeId__ header to choose the deserialization target type, and resolves that…
CVE-2026-47861 — CVSS 6.3 (medium): An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to…
CVE-2026-59322 — CVSS 6.3 (medium): The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat…
CVE-2026-47880 — CVSS 5.4 (medium): A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String JMS properties…
CVE-2026-47862 — CVSS 5.4 (medium): An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the…
CVE-2026-47859 — CVSS 5.4 (medium): RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the…
CVE-2026-59321 — CVSS 4.2 (medium): A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report THREADING=null (not…
CVE-2026-59292 — CVSS 3.2 (low): PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdir}/spring-integratio…