GHSA-x863-p983-p4f7
HIGHCVE-2026-41855In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization.
- Affected
- <= 5.3.39
- Fixed in
- not stated
- Weakness
- CWE-502
- Published
- 2026-06-09
- Source
- github