Security Advisory

CVE-2026-59322

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-27 18:04:50
Last updated 2026-08-28 22:46:40
Assigner vmware
CVSS score 6.3
State PUBLISHED

Description

The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain Map and constructs a GenericMessage with MutableMessageHeaders without sanitizing or filtering untrusted header names by default. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier