CVE-2026-47861
published 2026-08-27CVE-2026-47861: An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP…
PriorityP347medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.25%
16.6th percentile
An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing.
Spring Integration 7.1.0
Spring Integration 7.0.0 - 7.0.5
Spring Integration 6.5.0 - 6.5.10
Spring Integration 6.4.0 - 6.4.12
Spring Integration 5.5.21 and earlier
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_integration | <= 5.5.21 | — |
| spring | spring_integration | — | — |
| spring | spring_integration | 6.4.0 – 6.4.12 | — |
| spring | spring_integration | 6.5.0 – 6.5.10 | — |
| spring | spring_integration | 7.0.0 – 7.0.5 | — |
| vmware | spring_integration | < 5.5.22 | 5.5.22 |
| vmware | spring_integration | >= 6.4.0 < 6.4.13 | 6.4.13 |
| vmware | spring_integration | >= 6.5.0 < 6.5.11 | 6.5.11 |
| vmware | spring_integration | >= 7.0.0 < 7.0.5.1 | 7.0.5.1 |
| vmware | spring_integration | >= 7.1.0 < 7.1.0.1 | 7.1.0.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or extern
ghsa_unreviewed·2026-08-27
CVE-2026-47861 [MEDIUM] CWE-918 An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or extern
An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing.
Spring Integration 7.1.0
Spring Integration 7.0.0 - 7.0.5
Spring Integration 6.5.0 - 6.5.10
Spring Integration 6.4.0 - 6.4.12
Spring Integration 5.5.21 and earlier
VulDB
VMware Spring Integration up to 7.1.0 UDP Inbound Adapter server-side request forgery
vuldb·2026-08-27·CVSS 6.3
CVE-2026-47861 [MEDIUM] VMware Spring Integration up to 7.1.0 UDP Inbound Adapter server-side request forgery
A vulnerability identified as critical has been detected in VMware Spring Integration up to 5.5.21/6.4.12/6.5.10/7.0.5/7.1.0. This affects an unknown function of the component UDP Inbound Adapter. The manipulation leads to server-side request forgery.
This vulnerability is documented as CVE-2026-47861. The attack can be initiated remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-27
Published