{"id":"CVE-2026-41862","title":"Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to re…","summary":"Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to re…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-502"],"vendor":"broadcom","product":"spring_statemachine","affected":["spring_statemachine >= 3.2.0, < 3.2.5","spring_statemachine >= 4.0.0, < 4.0.2"],"patched":["spring_statemachine 4.0.2"],"published":"2026-06-23","updated":"2026-09-22","sourceUpdated":"2026-09-22T15:23:28.377","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-41862","references":[{"url":"https://spring.io/security/cve-2026-41862","label":"security@vmware.com"}],"tags":["nvd"],"epss":0.00746,"epssPercentile":0.5333,"ingestedAt":"2026-09-22T16:06:00.457Z","slug":"CVE-2026-41862","body":"## Overview\n\nSpring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502, deserialisation of untrusted data), which can lead to remote code execution inside the application JVM.\n\nAffected versions:\nSpring Statemachine 4.0.0 through 4.0.1\nSpring Statemachine 3.2.0 through 3.2.4\n\n## Affected\n\n- `spring_statemachine >= 3.2.0, < 3.2.5`\n- `spring_statemachine >= 4.0.0, < 4.0.2`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `spring_statemachine 4.0.2`","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}