Vmware · Spring Integration · CVE-2026-47862
**Name of the Vulnerable Software and Affected Versions**
Spring Integration versions 6.4.0 through 6.4.12
Spring Integration versions 6.5.0 through 6.5.10
Spring Integration versions 7.0.0 through 7.0.5
Spring Integration version 7.1.0
**Description**
A path traversal issue exists when a message reaches a ZipTransformer configured with `ZipResultType.FILE`. An attacker can manipulate the `file name` header to cause the resulting .zip archive to be written to an arbitrary filesystem path outside the designated `workDirectory`. Path traversal is a technique used to access files and directories that are stored outside the web root folder by manipulating variables such as file paths.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.