Executive brief
Spring Integration, a framework used to build enterprise messaging applications, reuses a single non-thread-safe script engine instance across concurrent message processing operations. This can cause one message's data (payload, headers) to leak into another message's script execution, leading to data exposure, incorrect processing, or service errors that could impact business operations.
Technical details
Spring Integration's script-backed channel implementation reuses a single ScriptEngine instance for every incoming message. When the underlying JSR-223 engine reports THREADING=null (indicating it is not thread-safe, such as the Kotlin kts engine), concurrent message processing creates a race condition that corrupts the engine's internal state. An attacker or legitimate user processing multiple messages concurrently can cause one message's variable bindings (payload, headers) to leak into another message's script evaluation context, or trigger spurious exceptions. The vulnerability requires concurrent message processing on the same script-backed channel to be triggered; patches are available in Spring Integration 5.5.22+, 6.4.13+, 6.5.11+, and 7.0.6+.
Affected products
- Spring Spring Integration 5.5.21 and earlier, 6.4.0–6.4.12, 6.5.0–6.5.10, 7.0.0–7.0.5, 7.1.0
Timeline
- 2026-08-27: disclosed