Vulnerability GHSA-85qj-f5wg-rwp9

High Risk
HIGH RISK
CVSS Score: 8.8
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 23, 2026 at 09:30 PM UTC
Spring Statemachine's Kryo-based persistence backends deserialize persisted state-machine contexts without enforcing a class allowlist
3.2.0 - 4.0.1
3.2.0 - 4.0.1

Summary

Spring Statemachine's Kryo-based persistence backends deserialize persisted state-machine contexts without enforcing a class allowlist

Details

Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM.

Affected versions: Spring Statemachine 4.0.0 through 4.0.1 Spring Statemachine 3.2.0 through 3.2.4

Timeline

Published
3 months ago
June 23, 2026 at 09:30 PM UTC
Fixed (4.0.2)
Unknown
Unknown
Last Modified
3 days ago
September 24, 2026 at 07:15 PM UTC