HIGH 8.8 Maven
Spring Statemachine's Kryo-based persistence backends deserialize persisted state-machine contexts without enforcing a class allowlist
GHSA-85qj-f5wg-rwp9 · CVE-2026-41862
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM.
Affected versions:
Spring Statemachine 4.0.0 through 4.0.1
Spring Statemachine 3.2.0 through 3.2.4
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-41862
- WEB https://github.com/spring-attic/spring-statemachine/commit/6b77ea6b729e5346d83e31f36c43818665d67384
- PACKAGE https://github.com/spring-attic/spring-statemachine
- WEB https://github.com/spring-attic/spring-statemachine/releases/tag/v4.0.2
- WEB https://spring.io/security/cve-2026-41862
Ready to move
Start Securing
Free, no credit card | First findings in minutes