SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-59274

MEDIUM · CVSS 6.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The UnZipTransformer in affected versions of Spring Integration is vulnerable due to its failure to limit the size and count of decompressed entries in zip archives. This oversight allows an attacker to craft a malicious zip file that can exhaust JVM heap memory, leading to a denial-of-service condition. Organizations using Spring Integration versions 6.4.0 to 7.1.0 should prioritize patching this vulnerability to mitigate potential service disruptions.

CVE
CVE-2026-59274
Severity
MEDIUM
CVSS
6.5
EPSS
0.24%

Original NVD Description

The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an attacker can send a zip archive that can exhaust JVM heap memory, causing a denial-of-service outage. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12

Related CVEs

Other vulnerabilities affecting the same vendor(s)