VYPR

Spring Statemachine

by Spring Projects

CVEs (1)

  • CVE-2026-41862Jun 23, 2026
    risk 0.00cvss epss

    Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application…