Junglewise Threat Intelligence

CVE-2026-41855: VMware Spring Framework deserialization in JMS message converters

CVE-2026-41855 · Severity: high · CVSS 8.1 · Published 2026-06-09

Technologies: VMware Spring Framework. Vendors: VMware, Spring.

Executive brief

Spring Framework's JMS message converters (MappingJackson2MessageConverter and JacksonJsonMessageConverter) deserve can instantiate arbitrary Java classes when processing messages from untrusted JMS brokers. An attacker with access to a JMS queue or topic can craft malicious messages to execute arbitrary code on the application server, potentially compromising confidentiality, integrity, and availability of the affected system.

Technical details

This vulnerability is a deserialization flaw (CWE-502) in Spring Framework's Jackson-based JMS message converters. When MappingJackson2MessageConverter or JacksonJsonMessageConverter processes JMS messages in an untrusted environment, they deserialize arbitrary class types without proper validation, allowing an attacker to instantiate gadget chain classes and achieve remote code execution. The attack requires network access to the JMS broker or the ability to send messages to affected queues/topics; no authentication or user interaction is required on the application side. The vulnerability affects Spring Framework versions 5.3.0–5.3.48, 6.1.0–6.1.27, 6.2.0–6.2.18, and 7.0.0–7.0.7. Patches are available in versions 6.2.19 and 7.0.8, though earlier versions (5.3.x and 6.1.x) do not have published patch versions in the advisory data.

Affected products

  • Spring Spring Framework 5.3.0 through 5.3.48
  • Spring Spring Framework 6.1.0 through 6.1.27
  • Spring Spring Framework 6.2.0 through 6.2.18
  • Spring Spring Framework 7.0.0 through 7.0.7

Timeline

  • 2026-06-09: disclosed: Vulnerability published to GitHub Advisory Database
  • 2026-06-09: patched: Patches released for Spring Framework 6.2.19 and 7.0.8

References

Related threats