CVE-2026-41862: Broadcom Spring Statemachine

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM. Affected versions: Spring Statemachine 4.0.0 through 4.0.1 Spring Statemachine 3.2.0 through 3.2.4

Affected products

  • Broadcom Spring Statemachine: from 3.2.0, before 3.2.5 (fixed in 3.2.5); from 4.0.0, before 4.0.2 (fixed in 4.0.2)

Published 2026-06-23. Last modified 2026-09-22.