External risk intelligence

Spring Integration Deserialization Remote Code Execution

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-47864

The vulnerability exists in an HTTP message converter used in Spring Integration. Applications utilizing this library often expose HTTP endpoints to handle incoming requests, making the interface reachable over the network. Because these endpoints are commonly deployed as web service or API gateways designed to receive external input, they represent a standard internet-facing attack surface.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability in Spring Integration could allow unauthenticated attackers to execute arbitrary code remotely by sending specially crafted HTTP requests. This issue arises from the way the software processes incoming data, potentially leading to a compromise of systems if malicious code is embedded in these requests. The primary concern is to confirm if our Spring Integration instances are affected and how they are configured to assess exposure.

  • Unauthenticated remote code execution is possible.
  • Confirms relevance and exposure in Spring Integration.
  • Assess your Spring Integration deployment for impact.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted HTTP request to an application that uses a vulnerable version of Spring Integration. The application's HTTP message converter will process this request, and if it contains a serialized Java object, the vulnerability will be triggered. This could lead to an attacker executing arbitrary code on the server.

  • Requires no authentication or user interaction.
  • Triggered by a serialized Java object in request body.
  • Results in arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A remote, unauthenticated attacker could achieve arbitrary code execution when an application uses the affected converter on an inbound HTTP endpoint, provided a Java deserialization "gadget" is present on the application's classpath. This could allow an attacker to compromise the affected system by exploiting how the application handles serialized Java objects within HTTP requests.

  • System control and data integrity at risk.
  • Malicious serialized objects sent in HTTP requests.
  • Complete system compromise and data theft.

Operational Fix

Recommended remediation, mitigation, and detection steps

Real-world impact requires understanding which teams manage Spring Integration deployments. Platform or application teams likely own the affected Java applications, while network and security teams must assess external exposure and potential impact. The first actionable step is to inventory all Spring Integration instances, prioritize those exposed externally or handling sensitive data, and identify their accountable owners before planning remediation.

  • Identify accountable platform/application owners.
  • Verify external reachability and business criticality.
  • Plan targeted remediation or risk reduction.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Spring Integration?

Spring Integration is a framework for Java applications that simplifies messaging and communication between different systems. It provides components, such as converters, to handle data transformation and integration tasks. In this context, it allows developers to build robust enterprise applications that can easily process various types of incoming and outgoing data streams over different protocols, including HTTP.

What does CWE-502 mean for CVE-2026-47864?

CWE-502 refers to Deserialization of Untrusted Data. For CVE-2026-47864, this means the software takes serialized Java objects from an HTTP request and rebuilds them into live objects without checking if they are safe. If an attacker includes a malicious object known as a 'gadget' in the request body, the application will inadvertently execute that code during the reconstruction process.

How is this vulnerability triggered?

An attacker triggers this by sending a specially crafted HTTP request with the content type set to application/x-java-serialized-object. The vulnerability does not trigger if the application does not use SerializingHttpMessageConverter on an inbound HTTP endpoint, or if there are no known gadget classes present on the application's Java classpath to facilitate the execution of arbitrary code.

Why should I care about this CVE?

Halo Surface Signal indicates this is a high-priority concern because the vulnerable converter is often used in web services or API gateways designed to receive network input. Because these interfaces are frequently exposed to the internet, they are reachable by remote, unauthenticated attackers who can attempt to compromise the system without needing any prior system access or user interaction.

What is the first step to address this?

Begin by creating an inventory of all applications within your environment that utilize the affected versions of Spring Integration. Once you have identified these instances, determine which ones are configured with inbound HTTP endpoints. Prioritize the assessment of these specific services, particularly those that are accessible over the network or handle sensitive business data.

References