PT-2026-82415 · Vmware · Spring Integration

·

CVE-2026-59274

·

Published

2026-08-27

·

Updated

2026-09-01

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Spring Integration versions 6.4.0 through 6.4.12 Spring Integration versions 6.5.0 through 6.5.10 Spring Integration versions 7.0.0 through 7.0.5 Spring Integration version 7.1.0
Description The UnZipTransformer does not limit the decompressed entry size or the entry count when processing archives. This allows an attacker to send a specially crafted zip archive, known as a zip-bomb, which can exhaust the JVM heap memory and lead to a denial-of-service outage.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59274

Affected Products

Spring Integration