Vmware · Spring Framework · CVE-2026-41855
**Name of the Vulnerable Software and Affected Versions**
Spring Framework versions 7.0.0 through 7.0.7
Spring Framework versions 6.2.0 through 6.2.18
Spring Framework versions 6.1.0 through 6.1.27
Spring Framework versions 5.3.0 through 5.3.48
**Description**
In an untrusted JMS environment, the `MappingJackson2MessageConverter` and `JacksonJsonMessageConverter` classes allow arbitrary class instantiation. This can lead to unauthorized actions through gadget class deserialization, a process where specially crafted data is used to trigger the execution of existing code sequences within the application to achieve malicious goals.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.