Junglewise Threat Intelligence

CVE-2026-59324: Spring Integration reply header leakage in fluxTransform with concurrent requests

CVE-2026-59324 · Severity: high · CVSS 8.2 · Published 2026-08-27

Vendors: Spring.

Executive brief

Spring Integration is a framework used to build message-driven applications. When using the fluxTransform() feature with asynchronous reordering functions, concurrent requests can have their security headers (including replyChannel, errorChannel, correlationId, and security/tenant headers) mixed up between different users or requests. This could allow one user to intercept another user's responses or route their errors, potentially exposing sensitive data or disrupting service operations.

Technical details

The vulnerability is a request/response mixing flaw in Spring Integration's fluxTransform() method when configured with asynchronous flux functions that emit raw payloads. The root cause is improper header isolation: reply headers (replyChannel, errorChannel, correlationId, and propagated security/tenant headers) are copied from the most recently consumed upstream message rather than being tied to the correct request context. An attacker does not need authentication; the vulnerability is exploited simply by making concurrent requests to an application using the affected pattern. An attacker can cause replies to be routed to incorrect channels, potentially reading responses intended for other users or injecting errors into other sessions. Patches are available for multiple versions: 6.5.11+, 6.4.13+, 7.0.6+, and 7.1.0+.

Affected products

  • Spring Spring Integration 7.1.0, 7.0.0–7.0.5, 6.5.0–6.5.10, 6.4.0–6.4.12, 5.5.21 and earlier

Timeline

  • 2026-08-27: disclosed: CVE-2026-59324 published

References