PatchSiren

Spring CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Spring CVE published 2026-08-27

CVE-2026-59324

The CVE-2026-59324 vulnerability affects Spring Integration versions 5.5.21 and earlier, 6.4.0 - 6.4.12, 6.5.0 - 6.5.10, 7.0.0 - 7.0.5, and 7.1.0. This issue occurs when using .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads in IntegrationFlow. Concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlat [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59322

The EmbeddedHeadersJsonMessageMapper in Spring Integration defaults to an overly permissive header parsing posture, allowing deserialization of untrusted header names. This vulnerability affects various versions of Spring Integration, including 7.1.0, 7.0.0-7.0.5, 6.5.0-6.5.10, 6.4.0-6.4.12, and 5.5.21 and earlier. Organizations using these versions should be aware of the potential for deserialization att [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59321

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T20:17:58.147Z and has not been modified since then. CVE-2026-59321 affects Spring Integration versions due to a reused ScriptEngine instance for every message on script-backed channels. This MEDIUM 4.2 CVSS score vulnerability can corrupt engine-internal state, potentially leaking one message's p [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59320

A medium-severity vulnerability (CVE-2026-59320) in VMware Spring Advanced Message Queuing Protocol can cause permanent consumption of link credits, leading to service disruption in message processing. This occurs when a container-level ErrorHandler is configured, and each delivery whose processing throws still permanently consumes one link credit. After initialCredits (default 100) failing messages, the [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59319

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T20:17:57.913Z and has not been modified since then. VMware Spring AI 2.0.0 contains a vulnerability in RedisChatMemoryRepository.findByMetadata(), allowing potential syntax injection attacks via RediSearch queries. An application passing user-controlled values to findByMetadata() on a tag-typed m [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59317

The CVE-2026-59317 vulnerability affects the DeadLetterPublishingRecovererFactory in Spring for Apache Kafka, allowing for potential attacks due to improper validation of the retry_topic-original-timestamp header. This issue impacts multiple versions, including 2.8.12 and earlier, 2.9.0 - 2.9.14, 3.0.0 - 3.3.16, 4.0.0 - 4.0.6, and 4.1.0. Organizations using these versions should prioritize patching to mit [truncated]

HIGH Spring CVE published 2026-08-27

CVE-2026-59316

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T20:17:57.667Z and has not been modified since then. The NVD entry is currently Analyzed. Organizations using Spring Authorization Server 1.4.0 through 1.4.11 and 1.5.0 through 1.5.8 should prioritize patching to prevent potential cross-site scripting attacks. The vulnerability can be exploited th [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59315

The CVE-2026-59315 vulnerability affects Spring Cloud Config Monitor, allowing Denial of Service attacks via malicious payloads. This issue impacts various versions of Spring Cloud Config, including 5.0.0 - 5.0.4, 4.3.0 - 4.3.4, 4.0.0 - 4.2.8, and 3.1.14 and earlier. Security teams and administrators should be aware of this vulnerability and take necessary defensive actions to mitigate potential risks.

LOW Spring CVE published 2026-08-27

CVE-2026-59306

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T20:17:56.990Z and has not been modified since then. CVE-2026-59306 indicates a potential for deserialization of untrusted types in Spring Cloud Stream, affecting versions 5.0.0 - 5.0.2, 4.3.0 - 4.3.3, and 4.2.0 - 4.2.6. The CVSS score is 3.1, with a severity of LOW. Users should review and apply [truncated]

LOW Spring CVE published 2026-08-27

CVE-2026-59304

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T20:17:56.760Z and has not been modified since then. The NVD entry is currently Analyzed. Users of Spring Cloud Stream, particularly those using affected versions 4.2.0-4.2.6, 4.3.0-4.3.3, and 5.0.0-5.0.2, should review and apply patches according to the vendor advisory and verify their deployment [truncated]

LOW Spring CVE published 2026-08-27

CVE-2026-59303

CVE-2026-59303 is a vulnerability in Spring Cloud Stream that allows for an unbounded dynamic destination cache size, affecting versions 5.0.0 - 5.0.2, 4.3.0 - 4.3.3, and 4.2.0 - 4.2.6. This issue has a CVSS score of 3.1 and is classified as LOW severity. Users of affected versions should review and apply patches. The vulnerability is related to an unbounded dynamic destination cache size in Spring Cloud [truncated]

LOW Spring CVE published 2026-08-27

CVE-2026-59302

CVE-2026-59302 debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T20:17:56.520Z and has not been modified since then. The vulnerability affects Spring Cloud Stream versions 4.2.0-4.2.6, 4.3.0-4.3.3, and 5.0.0-5.0.2, indicating a potential for logging sensitive data. Defenders and administrators responsible for Spring Cloud Stream deployments should assess exposure and [truncated]

LOW Spring CVE published 2026-08-27

CVE-2026-59301

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T20:17:56.407Z and has not been modified since then. This CVE affects multiple product versions and requires coordinated review across development, operations, and security teams to ensure comprehensive mitigation and minimize potential exposure. Affected teams should also consider compensating co [truncated]

LOW Spring CVE published 2026-08-27

CVE-2026-59300

The CVE-2026-59300 record indicates a potential for logging sensitive data in Spring Cloud Function versions 3.2.16 and earlier, 4.2.0 - 4.2.7, 4.3.0 - 4.3.4, and 5.0.0 - 5.0.3. This issue has a CVSS score of 3.1 and is classified as LOW severity. Affected deployments should review their logging configurations to prevent exposure of sensitive data. The CVE record was published on 2026-08-27T20:17:56.293Z [truncated]

LOW Spring CVE published 2026-08-27

CVE-2026-59299

CVE-2026-59299 is a vulnerability in Spring Cloud Function that can potentially poison the base function through composition lookup. This affects versions 3.2.16 and earlier, 4.2.0 - 4.2.7, 4.3.0 - 4.3.4, and 5.0.0 - 5.0.3. Users should verify their inventory and apply patches or compensating controls as available. The CVE record was published on 2026-08-27T20:17:56.173Z and has not been modified since th [truncated]

LOW Spring CVE published 2026-08-27

CVE-2026-59297

The CVE-2026-59297 record indicates that the implementation of the isSecure() call in ServerlessHttpServletRequest does not verify the actual scheme. This vulnerability affects Spring Cloud Function versions 4.2.0 through 4.2.7, 4.3.0 through 4.3.4, and 5.0.0 through 5.0.3. Users should assess potential impacts and verify the implementation of the isSecure() call. Limited information is available on poten [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59294

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T20:17:55.583Z and has not been modified since then. The vulnerability affects VMware Spring AI versions, with details provided in the NVD entry and vendor advisory. Evidence is based on official CVE Program and NVD records. The vulnerability has a CVSS score of 5.9 and could potentially lead to h [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59293

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T20:17:55.460Z and has not been modified since then. The NVD entry is currently Analyzed. Security teams responsible for Spring Integration deployments, particularly those using SMB protocol, should review and apply patches to mitigate potential NTLM relay and content-tampering attacks. This inclu [truncated]

LOW Spring CVE published 2026-08-27

CVE-2026-59292

The PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore in Spring Integration, persists its state to a properties file located in ${java.io.tmpdir}/spring-integration/metadata-store.properties with world-readable permissions. This could potentially expose sensitive data, such as authentication credentials or encryption keys. The issue affects multiple versions of Spring Integ [truncated]

LOW Spring CVE published 2026-08-27

CVE-2026-59291

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T20:17:55.227Z and has not been modified since then. CVE-2026-59291 is a potential arbitrary file read and SSRF vulnerability in Spring Cloud Function versions 4.2.0-4.2.7, 4.3.0-4.3.4, and 5.0.0-5.0.3. The CVSS score is 2 (Low). The vulnerability could allow attackers to read arbitrary files and [truncated]

HIGH Spring CVE published 2026-08-27

CVE-2026-59288

The GraphiQL page bundled with Spring for GraphQL sends requests to the GraphQL endpoints of the application. An attacker can share a malicious URL so that the victim's browser might leak confidential information to the attacker's website. This issue affects multiple versions of Spring for GraphQL, including 2.0.0 - 2.0.4, 1.4.0 - 1.4.6, 1.1.0 - 1.3.9, and 1.0.0 - 1.0.7. The vulnerability is related to ho [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59287

CVE-2026-59287 is a Denial of Service vulnerability in Spring for GraphQL when using the WebSocket client with keepAlive enabled. Affected versions are Spring for GraphQL 2.0.0 - 2.0.4, 1.4.0 - 1.4.6, and 1.3.0 - 1.3.9. The CVSS score is 5.9, with a severity of MEDIUM. Organizations should review their inventory and apply patches or mitigations to prevent potential Denial of Service attacks. The CVE recor [truncated]

CRITICAL Spring CVE published 2026-08-27

CVE-2026-59283

The CVE-2026-59283 vulnerability affects applications using SimpleEvaluationContext to evaluate Spring Expression Language (SpEL) expressions when the SpEL expression compiler is active, allowing for a safety guard bypass. This critical vulnerability impacts multiple Spring Framework versions: 5.2.25.RELEASE and earlier, 5.3.0 - 5.3.49, 6.0.0 - 6.0.30, 6.1.0 - 6.1.28, 6.2.0 - 6.2.19, and 7.0.0 - 7.0.8. Th [truncated]

HIGH Spring CVE published 2026-08-27

CVE-2026-59282

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T20:17:54.370Z and has not been modified since then. This Denial of Service (DoS) vulnerability affects Spring Framework applications using Spring's data binding infrastructure, with versions 7.0.0 - 7.0.8, 6.2.0 - 6.2.19, 6.1.0 - 6.1.28, 6.0.0 - 6.0.30, 5.3.0 - 5.3.49, and 5.2.25.RELEASE and earl [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59281

The CVE-2026-59281 vulnerability affects Spring MVC and WebFlux applications, allowing for arbitrary HTML/JavaScript code injection and potentially resulting in a reflected cross-site scripting (XSS) vulnerability. Security teams, developers, and IT administrators responsible for Spring Framework applications should be aware of this vulnerability and take necessary defensive actions to prevent reflected X [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59280

Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller returns a view name derived from untrusted input and FreeMarker is configured to resolve templates through SpringTemplateLoader. This CVE record was published on 2026-08-27T17:18:57.780Z and has not been modified since then. The NVD entry is currently Analyzed. Developers and adminis [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59278

CVE-2026-59278 is a vulnerability in Spring for Apache Kafka, specifically in JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper, which include java.net in their default trusted packages list. This allows an external Kafka producer to inject a java.net.InetAddress type via the spring_json_header_types message header, potentially leading to remote code execution. The CVE record was published on 2026-08-27T [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59275

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T06:17:22.073Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Spring AMQP versions 4.1.0, 4.0.0 - 4.0.4, 3.2.0 - 3.2.12, and 2.4.18 and earlier. A single hostile AMQP message can terminate the entire consumer JVM (System.exit(99)), not just th [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59274

The UnZipTransformer in Spring Integration does not limit decompressed entry size or entry count when processing archives, allowing an attacker to exhaust JVM heap memory and cause a denial-of-service outage. This vulnerability affects Spring Integration versions 6.4.0 - 6.4.12, 6.5.0 - 6.5.10, 7.0.0 - 7.0.5, and 7.1.0. Organizations should prioritize patching to prevent potential outages. The CVE record [truncated]

MEDIUM Spring CVE published 2026-08-27

CVE-2026-59271

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-27T06:17:21.510Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects RabbitMQ and Spring AMQP, potentially exposing admin credentials in exception messages during the aliveness check. Teams using these technologies should review configurations and up [truncated]