PT-2026-47666 · Vmware · Spring Framework

·

CVE-2026-41855

·

Published

2026-06-09

·

Updated

2026-06-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spring Framework versions 7.0.0 through 7.0.7 Spring Framework versions 6.2.0 through 6.2.18 Spring Framework versions 6.1.0 through 6.1.27 Spring Framework versions 5.3.0 through 5.3.48
Description In an untrusted JMS environment, the MappingJackson2MessageConverter and JacksonJsonMessageConverter classes allow arbitrary class instantiation. This can lead to unauthorized actions through gadget class deserialization, a process where specially crafted data is used to trigger the execution of existing code sequences within the application to achieve malicious goals.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41855
GHSA-X863-P983-P4F7

Affected Products

Spring Framework