Spring Integration 7.1.0
Spring Integration 7.0.0 - 7.0.5
Spring Integration 6.5.0 - 6.5.10
Spring Integration 6.4.0 - 6.4.12
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://spring.io/security/cve-2026-59274 |
|
Thu, 27 Aug 2026 08:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring Integration |
|
| Weaknesses | CWE-400 | |
| Vendors & Products |
Spring
Spring spring Integration |
Thu, 27 Aug 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denial-of-service outage. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 | |
| Title | Unbounded decompression in UnZipTransformer enables zip-bomb DoS | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-08-27T05:21:43.138Z
Reserved: 2026-07-04T18:13:09.972Z
Link: CVE-2026-59274
No data.
Status : Received
Published: 2026-08-27T06:17:21.820
Modified: 2026-08-27T06:17:21.820
Link: CVE-2026-59274
No data.
OpenCVE Enrichment
Updated: 2026-08-27T07:45:03Z
-
CWE-400
Uncontrolled Resource Consumption