Spring Framework Unsafe Deserialization via Jackson JMS Converters

HIGH | JUNE 08, 2026 | CVE-2026-41855

Description

In an untrusted JMS environment, org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter allow arbitrary class instantiation, which can lead to unauthorized actions via gadget class deserialization.

Affected Spring Products and Versions

Spring Framework:

  • 7.0.0 - 7.0.7
  • 6.2.0 - 6.2.18
  • 6.1.0 - 6.1.27
  • 5.3.48 and earlier

Mitigation

Users of affected versions should upgrade to the corresponding fixed version.
Fix versionAvailability
7.0.8OSS
7.0.7.1Enterprise Support Only
6.2.19OSS
6.2.18.1Enterprise Support Only
6.1.28Enterprise Support Only
5.3.49Enterprise Support Only

For a trusted JMS environment (the most common use case), no mitigation steps are necessary.

For an untrusted JMS environment, users of affected versions should upgrade to the corresponding fixed version and limit the packages authorized for deserialization using the new setTrustedPackages(String... trustedPackages) methods.

Credit

This issue was responsibly reported by wo1enca1ca1.

History

  • 2026-06-08: Initial vulnerability report published.

Get ahead

VMware offers training and certification to turbo-charge your progress.

Learn more

Get support

Tanzu Spring offers support and binaries for OpenJDK™, Spring, and Apache Tomcat® in one simple subscription.

Learn more

Upcoming events

Check out all the upcoming events in the Spring community.

View all