Vulnerability Details CVE-2026-47861
An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker's choosing.
Spring Integration 7.1.0
Spring Integration 7.0.0 - 7.0.5
Spring Integration 6.5.0 - 6.5.10
Spring Integration 6.4.0 - 6.4.12
Spring Integration 5.5.21 and earlier
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 16.4%
CVSS Severity
CVSS v3 Score 6.3