CVE-2026-59324
published 2026-08-27CVE-2026-59324: When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same…
PriorityP345high8.2CVSS 3.1
AVNACLPRNUINSUCHILAN
EPSS
0.24%
14.6th percentile
When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message was most recently consumed upstream.
Spring Integration 7.1.0
Spring Integration 7.0.0 - 7.0.5
Spring Integration 6.5.0 - 6.5.10
Spring Integration 6.4.0 - 6.4.12
Spring Integration 5.5.21 and earlier
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_integration | <= 5.5.21 | — |
| spring | spring_integration | — | — |
| spring | spring_integration | 6.4.0 – 6.4.12 | — |
| spring | spring_integration | 6.5.0 – 6.5.10 | — |
| spring | spring_integration | 7.0.0 – 7.0.5 | — |
| vmware | spring_integration | < 5.5.22 | 5.5.22 |
| vmware | spring_integration | >= 6.4.0 < 6.4.13 | 6.4.13 |
| vmware | spring_integration | >= 6.5.0 < 6.5.11 | 6.5.11 |
| vmware | spring_integration | >= 7.0.0 < 7.0.5.1 | 7.0.5.1 |
| vmware | spring_integration | >= 7.1.0 < 7.1.0.1 | 7.1.0.1 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
org.springframework.integration/spring-integration-core: Spring Integration: Information disclosure via cross-message header leakage
vendor_redhat·2026-08-27·CVSS 8.2
CVE-2026-59324 [HIGH] CWE-821 org.springframework.integration/spring-integration-core: Spring Integration: Information disclosure via cross-message header leakage
org.springframework.integration/spring-integration-core: Spring Integration: Information disclosure via cross-message header leakage
A flaw was found in Spring Integration. When an IntegrationFlow uses `.fluxTransform()` with an asynchronous `fluxFunction` that emits raw payloads, concurrent requests on the same `FluxMessageChannel` subscription can have their reply headers copied from other messages. This information disclosure vulnerability allows an attacker to potentially access sensitive data such as `replyChannel`, `errorChannel`, `correlationId`, or other security-related headers from concurrent requests.
Statement: A concurrency-related context leakage vulnerability exists in Spring Integration's reactive fluxTransform() function when processing raw payloads on a shared FluxMessa
GHSA
When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply hea
ghsa_unreviewed·2026-08-27
CVE-2026-59324 [HIGH] CWE-362 When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply hea
When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message was most recently consumed upstream.
Spring Integration 7.1.0
Spring Integration 7.0.0 - 7.0.5
Spring Integration 6.5.0 - 6.5.10
Spring Integration 6.4.0 - 6.4.12
Spring Integration 5.5.21 and earlier
VulDB
VMware Spring Integration up to 7.1.0 Flux Transform fluxTransform race condition
vuldb·2026-08-27·CVSS 8.2
CVE-2026-59324 [HIGH] VMware Spring Integration up to 7.1.0 Flux Transform fluxTransform race condition
A vulnerability classified as critical was found in VMware Spring Integration up to 5.5.21/6.4.12/6.5.10/7.0.5/7.1.0. This affects the function fluxTransform of the component Flux Transform. The manipulation results in race condition.
This vulnerability is cataloged as CVE-2026-59324. The attack may be launched remotely. There is no exploit available.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-59324 apache-sshd: Spring Integration: Information disclosure via cross-message header leakage [fedora-all]
bugzilla·2026-09-08·CVSS 8.2
CVE-2026-59324 [HIGH] CVE-2026-59324 apache-sshd: Spring Integration: Information disclosure via cross-message header leakage [fedora-all]
CVE-2026-59324 apache-sshd: Spring Integration: Information disclosure via cross-message header leakage [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message was most recently consumed upstream.
Spring Integration 7.1.0
Spring Integration 7.0.0 - 7.0.5
Spring Integration 6.5.0 - 6.5.10
Spring In
Bugzilla
CVE-2026-59324 org.springframework.integration/spring-integration-core: Spring Integration: Information disclosure via cross-message header leakage
bugzilla·2026-08-27·CVSS 8.2
CVE-2026-59324 [HIGH] CVE-2026-59324 org.springframework.integration/spring-integration-core: Spring Integration: Information disclosure via cross-message header leakage
CVE-2026-59324 org.springframework.integration/spring-integration-core: Spring Integration: Information disclosure via cross-message header leakage
When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message was most recently consumed upstream.
Spring Integration 7.1.0
Spring Integration 7.0.0 - 7.0.5
Spring Integration 6.5.0 - 6.5.10
Spring Integration 6.4.0 - 6.4.12
Spring Integration 5.5.21 and earlier
2026-08-27
Published