CVE-2026-59321: Shared JSR-223 ScriptEngine evaluated concurrently without THREADING check

Published Aug 27, 2026
·
Updated

A single ScriptEngine instance is reused for every message on a script-backed channel. For JSR-223 engines that report THREADING=null (not thread-safe, e.g. the Kotlin kts engine), concurrent message processing can corrupt engine-internal state, potentially leaking one message's payload/headers bindings into another message's script evaluation or throwing spurious exceptions. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier

Affected Software

1 affected component
Spring Spring Integration=7.1.0, >7.0.0<7.0.5, >=6.5.0<=6.5.10, >=6.4.0<=6.4.12, <=5.5.21

Event History

Aug 27, 2026
CVE Published
via MITRE·06:04 PM
Data Sourced
via MITRE·06:04 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverity

Frequently Asked Questions

1

Which deployments are exposed to this issue?

Deployments using a script-backed channel with a JSR-223 ScriptEngine that reports THREADING=null are exposed. The Kotlin kts engine is identified as an example of such an engine, and exposure requires concurrent message processing.

2

What access does an attacker need to exploit the issue?

The supplied vector indicates network access, high attack complexity, low privileges, and no user interaction. Exploitation depends on causing concurrent processing of messages through the affected script-backed channel.

3

What can happen if the race condition is triggered?

Engine-internal state can be corrupted, which may cause payload or header bindings from one message to be used during another message's script evaluation. It can also produce spurious exceptions.

4

Which Spring Integration versions are affected?

Affected versions are 7.1.0; 7.0.0 through 7.0.5; 6.5.0 through 6.5.10; 6.4.0 through 6.4.12; and 5.5.21 and earlier.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203