CVE-2026-59322: VMware Spring Integration
Medium severity, CVSS 6.3. EPSS: 0.3% chance of exploitation in the next 30 days.
The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain Map and constructs a GenericMessage with MutableMessageHeaders without sanitizing or filtering untrusted header names by default. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Affected products
- VMware Spring Integration: before 5.5.22 (fixed in 5.5.22); from 6.4.0, before 6.4.13 (fixed in 6.4.13); from 6.5.0, before 6.5.11 (fixed in 6.5.11); from 7.0.0, before 7.0.5.1 (fixed in 7.0.5.1); from 7.1.0, before 7.1.0.1 (fixed in 7.1.0.1)
Published 2026-08-27. Last modified 2026-09-01.