Junglewise Threat Intelligence

CVE-2026-59311: Spring Integration symlink vulnerability in Zip/UnZip transformer

CVE-2026-59311 · Severity: medium · CVSS 6.8 · Published 2026-08-27

Vendors: Spring.

Executive brief

Spring Integration, a framework for building enterprise messaging applications, contains a symlink attack vulnerability in its Zip/UnZip transformer component. A local attacker with unprivileged access to the same system can pre-create a malicious symlink to redirect compressed file output to arbitrary directories, potentially enabling unauthorized file creation, overwriting, or data exfiltration within the application's filesystem.

Technical details

The vulnerability is a symlink attack (TOCTOU/insecure temporary file) in Spring Integration's Zip/UnZip transformer. An unprivileged local attacker can pre-create /tmp/ziptransformer as a symlink pointing to a directory of their choosing before the application starts processing archive operations. The transformer does not follow secure temporary file handling practices, failing to check for or safely handle symlinks. This allows the attacker to redirect all transformer output to an arbitrary location, potentially overwriting files or accessing sensitive data. The issue affects Spring Integration versions 6.4.0–6.4.12, 6.5.0–6.5.10, and 7.0.0–7.0.5 (7.1.0 also affected). A patch is expected from Spring Security.

Affected products

  • Spring Spring Integration 6.4.0–6.4.12, 6.5.0–6.5.10, 7.0.0–7.0.5, 7.1.0

Timeline

  • 2026-08-27: disclosed

References