Spring Product Security Update Advisory (CVE-2026-41862)
Overview
A security update has been released to address a vulnerability in Spring products. The vulnerability is CVE-2026-41862, a deserialization vulnerability (the process of converting stored data back into an object) in Spring StateMachine.
Affected Products
- Spring Statemachine 4.0.0 Through 4.0.1.
- Spring Statemachine 3.2.0 Through 3.2.4.
Fixed Versions
- Spring StateMachine 4.0.2.
- Spring StateMachine 4.0.1.1.
- Spring StateMachine 3.2.5.
Notes
- You must update to the latest version that includes the Vulnerability Patch for this vulnerability, following the instructions on the reference site.
- CVE-2026-41862 is described as “Kryo deserialization of persisted context without class allowlist.”