Spring Integration 7.1.0
Spring Integration 7.0.0 - 7.0.5
Spring Integration 6.5.0 - 6.5.10
Spring Integration 6.4.0 - 6.4.12
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-47862 |
|
Thu, 27 Aug 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring Integration |
|
| Vendors & Products |
Spring
Spring spring Integration |
Thu, 27 Aug 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default) can cause the resulting .zip archive to be written to an arbitrary filesystem path outside the configured workDirectory. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 | |
| Title | ZipTransformer uses file_name header to build workDirectory path without sanitization | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-08-26T23:28:47.655Z
Reserved: 2026-05-20T10:00:55.156Z
Link: CVE-2026-47862
No data.
Status : Received
Published: 2026-08-27T01:17:33.313
Modified: 2026-08-27T01:17:33.313
Link: CVE-2026-47862
No data.
OpenCVE Enrichment
Updated: 2026-08-27T01:30:13Z
No weakness.