CVE-2026-41862 - Spring Statemachine Deserialisation Vulnerability
CVE ID :CVE-2026-41862 Published : June 23, 2026, 8:59 p.m. | 2 hours, 11 minutes ago Description :Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deserialise persisted state-machine contexts without enforcing a class allowlist (CWE-502,...