CVE-2026-59322
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
27/08/2026
Last modified:
28/08/2026
Description
The EmbeddedHeadersJsonMessageMapper defaults to an overly permissive header parsing posture in its constructor. When decodeNativeFormat processes raw byte payloads, it deserializes embedded JSON headers into a plain Map and constructs a GenericMessage with MutableMessageHeaders without sanitizing or filtering untrusted header names by default.<br />
Spring Integration 7.1.0<br />
Spring Integration 7.0.0 - 7.0.5<br />
Spring Integration 6.5.0 - 6.5.10<br />
Spring Integration 6.4.0 - 6.4.12<br />
Spring Integration 5.5.21 and earlier
Impact
Base Score 3.x
6.30
Severity 3.x
MEDIUM



