vmware / spring_integration
15 known vulnerabilities in vmware spring_integration.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2026-59307 | Medium | 0.3% | 8.0 | An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deser… | |
| CVE-2026-59324 | Medium | 0.2% | 8.2 | When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fl… | |
| CVE-2026-40987 | Medium | 0.2% | 7.1 | A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywher… | |
| CVE-2026-47864 | Low | 4.1% | 6.4 | SerializingHttpMessageConverter deserializes the body of incoming HTTP requests … | |
| CVE-2026-59311 | Low | 0.4% | 6.8 | A local unprivileged user on the same host can redirect all Zip/UnZip transforme… | |
| CVE-2026-47862 | Low | 0.3% | 5.4 | An attacker who can set the file_name header on a message reaching a ZipTransfor… | |
| CVE-2026-47861 | Low | 0.3% | 6.3 | An unauthenticated remote attacker who can send a single UDP packet to a Spring … | |
| CVE-2026-47856 | Low | 0.2% | 6.3 | Spring Integration's JSON to object conversion uses the json__TypeId__ header to… | |
| CVE-2026-59274 | Low | 0.2% | 6.5 | The UnZipTransformer does not limit decompressed entry size or entry count when … | |
| CVE-2026-47859 | Low | 0.2% | 5.4 | RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound ada… | |
| CVE-2026-59293 | Low | 0.2% | 6.6 | Unless the application explicitly raises smbMinVersion, the jCIFS client will ne… | |
| CVE-2026-59322 | Low | 0.2% | 6.3 | The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header par… | |
| CVE-2026-47880 | Low | 0.2% | 5.4 | A producer who can publish to a JMS destination consumed by any Spring Integrati… | |
| CVE-2026-59292 | Low | 0.1% | 3.2 | PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStor… | |
| CVE-2026-59321 | Low | 0.1% | 4.2 | A single ScriptEngine instance is reused for every message on a script-backed ch… |