CVE-2026-47856 | Spring Integration up to 7.1.0 JSON Deserializer json__TypeId__ deserialization

SecurityVulns

A vulnerability, which was classified as critical, has been found in Spring Integration up to 5.5.21/6.4.12/6.5.10/7.0.5/7.1.0. This vulnerability affects unknown code of the component JSON Deserializer. The manipulation of the argument json__TypeId__ leads to deserialization.

This vulnerability is uniquely identified as CVE-2026-47856. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More