Junglewise Threat Intelligence

CVE-2026-47861: Spring Framework UDP inbound adapter arbitrary datagram reflection

CVE-2026-47861 · Severity: medium · CVSS 6.3 · Published 2026-08-27

Technologies: VMware Spring Integration. Vendors: VMware.

Executive brief

Spring Integration is a middleware library used to build message-driven applications and integrate systems across enterprise networks. An unauthenticated attacker can send a single UDP packet to a server running a vulnerable UDP inbound adapter, causing it to automatically transmit outbound UDP datagrams to any arbitrary host and port the attacker specifies. This can be abused to amplify attacks against third parties or probe internal network infrastructure without authorization.

Technical details

Spring Integration UDP inbound adapter contains a vulnerability that allows unauthenticated remote attackers to trigger arbitrary outbound UDP traffic via a maliciously crafted inbound UDP packet. The vulnerability appears to be a UDP reflection or amplification flaw in the adapter's packet handling logic, where attacker-controlled destination information in the received packet is not properly validated before being used to generate responses. An attacker with network access to the UDP port can exploit this with a single crafted packet to cause the vulnerable server to send datagrams to internal or external targets of the attacker's choice, enabling reflection attacks, UDP amplification, or network reconnaissance. Patches are available in Spring Integration 5.5.22+, 6.4.13+, 6.5.11+, and 7.0.6+.

Affected products

  • VMware Spring Integration 5.5.0 through 5.5.21, 6.4.0 through 6.4.12, 6.5.0 through 6.5.10, 7.0.0 through 7.0.5, 7.1.0

Timeline

  • 2026-08-27: disclosed

References

Related threats