Known Vulnerabilities for Spring Integration by Vmware
Listed below are 10 of the newest known vulnerabilities associated with "Spring Integration" by "Vmware".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-59324 json | When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurren... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-59322 json | The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeN... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-59321 json | A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report THREAD... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-59311 json | A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choosing b... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-59307 json | An operator who calls JdbcMessageStore.addAllowedPatterns(...) to restrict deserialization receives no protection at all when... | Not Provided | 2026-08-27 | 2026-08-29 |
| CVE-2026-59293 json | Unless the application explicitly raises smbMinVersion, the jCIFS client will negotiate down to SMB1/CIFS, which lacks mandat... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-59292 json | PropertiesPersistingMetadataStore, the default file-based ConcurrentMetadataStore, persists its state to ${java.io.tmpdir}/sp... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-59280 json | Applications using Spring Framework's FreeMarker integration may be vulnerable to a path traversal attack when a controller r... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-59274 json | The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacke... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-50201 json | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. ... | Not Provided | 2026-06-17 | 2026-06-18 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vmware | Spring Integration | 5.4.0 | |||
| Application | Vmware | Spring Integration | 5.4.0 | |||
| Application | Vmware | Spring Integration | 5.4.0 | |||
| Application | Vmware | Spring Integration | 5.3.2 | |||
| Application | Vmware | Spring Integration | 5.3.1 | |||
| Application | Vmware | Spring Integration | 5.3.0 | |||
| Application | Vmware | Spring Integration | 5.3.0 | |||
| Application | Vmware | Spring Integration | 5.3.0 | |||
| Application | Vmware | Spring Integration | 5.3.0 | |||
| Application | Vmware | Spring Integration | 5.3.0 | |||
| Application | Vmware | Spring Integration | 5.3.0 | |||
| Application | Vmware | Spring Integration | 5.2.8 | |||
| Application | Vmware | Spring Integration | 5.2.7 | |||
| Application | Vmware | Spring Integration | 5.2.6 | |||
| Application | Vmware | Spring Integration | 5.2.5 | |||
| Application | Vmware | Spring Integration | 5.2.4 | |||
| Application | Vmware | Spring Integration | 5.2.3 | |||
| Application | Vmware | Spring Integration | 5.2.2 | |||
| Application | Vmware | Spring Integration | 5.2.1 | |||
| Application | Vmware | Spring Integration | 5.2.0 |