Vulnerability GHSA-85qj-f5wg-rwp9
High Risk
HIGH RISK
CVSS Score: 8.8
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 months ago
June 23, 2026 at 09:30 PM UTC
Spring Statemachine's Kryo-based persistence backends deserialize persisted state-machine contexts without enforcing a class allowlist
3.2.0 - 4.0.1
3.2.0 - 4.0.1
Summary
Spring Statemachine's Kryo-based persistence backends deserialize persisted state-machine contexts without enforcing a class allowlist
Details
Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM.
Affected versions: Spring Statemachine 4.0.0 through 4.0.1 Spring Statemachine 3.2.0 through 3.2.4
Impacted packages
Timeline
Published
3 months ago
June 23, 2026 at 09:30 PM UTC
Fixed (4.0.2)
Unknown
Unknown
Last Modified
3 days ago
September 24, 2026 at 07:15 PM UTC