logo

Multiple Security Flaws Addressed in Core Java Application Subsystems

ID: 3d0272e7-8860-5f03-815d-8ad2b569f7e0

STIX ID: report--3d0272e7-8860-5f03-815d-8ad2b569f7e0

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-11

Date Updated: 2026-06-11

Author: Do Son

...
...

This advisory details multiple critical vulnerabilities in Spring GraphQL and related integration modules that can enable remote code execution via unsafe deserialization, cross-site WebSocket/session hijacking, arbitrary class loading through crafted Kafka/Pulsar headers, and path traversal in synchronization components. Administrators are strongly advised to apply the listed maintenance updates (e.g., Kafka 4.0.6 / 3.3.16, Pulsar 2.0.6 / 1.2.18, synchronizer 7.0.5) immediately to mitigate exploitation risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.