CVE-2026-59322
published 2026-08-27CVE-2026-59322: The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte…
PriorityP336medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.21%
11.4th percentile
The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain Map and constructs a GenericMessage with MutableMessageHeaders without sanitizing or filtering untrusted header names by default.
Spring Integration 7.1.0
Spring Integration 7.0.0 - 7.0.5
Spring Integration 6.5.0 - 6.5.10
Spring Integration 6.4.0 - 6.4.12
Spring Integration 5.5.21 and earlier
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_integration | <= 5.5.21 | — |
| spring | spring_integration | — | — |
| spring | spring_integration | 6.4.0 – 6.4.12 | — |
| spring | spring_integration | 6.5.0 – 6.5.10 | — |
| spring | spring_integration | 7.0.0 – 7.0.5 | — |
| vmware | spring_integration | < 5.5.22 | 5.5.22 |
| vmware | spring_integration | >= 6.4.0 < 6.4.13 | 6.4.13 |
| vmware | spring_integration | >= 6.5.0 < 6.5.11 | 6.5.11 |
| vmware | spring_integration | >= 7.0.0 < 7.0.5.1 | 7.0.5.1 |
| vmware | spring_integration | >= 7.1.0 < 7.1.0.1 | 7.1.0.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
VMware Spring Integration up to 7.1.0 Header Parsing input validation
vuldb·2026-08-27·CVSS 6.3
CVE-2026-59322 [MEDIUM] VMware Spring Integration up to 7.1.0 Header Parsing input validation
A vulnerability marked as critical has been reported in VMware Spring Integration up to 5.5.21/6.4.12/6.5.10/7.0.5/7.1.0. Impacted is the function EmbeddedHeadersJsonMessageMapper.decodeNativeFormat of the component Header Parsing. This manipulation causes improper input validation.
The identification of this vulnerability is CVE-2026-59322. It is possible to initiate the attack remotely. There is no exploit available.
GHSA
The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor.
ghsa_unreviewed·2026-08-27
CVE-2026-59322 [MEDIUM] CWE-20 The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor.
The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain Map and constructs a GenericMessage with MutableMessageHeaders without sanitizing or filtering untrusted header names by default.
Spring Integration 7.1.0
Spring Integration 7.0.0 - 7.0.5
Spring Integration 6.5.0 - 6.5.10
Spring Integration 6.4.0 - 6.4.12
Spring Integration 5.5.21 and earlier
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-27
Published