Junglewise Threat Intelligence

CVE-2026-47856: Spring Integration unsafe JSON deserialization via TypeId header

CVE-2026-47856 · Severity: medium · CVSS 6.3 · Published 2026-08-27

Technologies: Pivotal Software Spring Integration.

Executive brief

Spring Integration, a middleware framework used to integrate applications and services, contains a vulnerability in its JSON message processing. An attacker can craft a malicious JSON message with a specially crafted TypeId header to force the application to deserialize and instantiate arbitrary classes, potentially leading to code execution or other system compromise.

Technical details

Spring Integration's JSON-to-object conversion mechanism uses the json__TypeId__ HTTP header to determine which class to deserialize JSON data into. The vulnerable code resolves this header value to a Java class using ClassUtils.forName without any allow-list or type validation. An attacker with network access to a Spring Integration endpoint can send a crafted JSON request with a malicious TypeId header pointing to a dangerous class on the classpath, achieving arbitrary deserialization and potentially remote code execution. The vulnerability affects Spring Integration versions 5.5.21 and earlier, 6.4.0–6.4.12, 6.5.0–6.5.10, and 7.0.0–7.0.5, with version 7.1.0 also affected.

Affected products

  • Pivotal Software Spring Integration 5.5.21 and earlier, 6.4.0–6.4.12, 6.5.0–6.5.10, 7.0.0–7.0.5, 7.1.0

Timeline

  • 2026-08-27: disclosed

References