CVE-2026-41862: Kryo deserialization of persisted context without class allowlist
Spring
·
2026-06-11
·
via Spring Security Advisories
Description Spring Statemachine's Kryo-based persistence backends (JPA, MongoDB, Redis and ZooKeeper) deseria…
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。