Vulnerability Details CVE-2026-47878
DefaultExecutionContextSerializer, used by default in Spring Batch's JDBC job repository, passes Base64-decoded bytes directly to ObjectInputStream.readObject() without an ObjectInputFilter that restricts types to a trusted class allowlist.
Spring Batch 6.0.0 - 6.0.4
Spring Batch 5.2.6 and earlier
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 16.1%
CVSS Severity
CVSS v3 Score 5.6
Products affected by CVE-2026-47878
-
cpe:2.3:a:broadcom:spring_batch:6.0.0
-
cpe:2.3:a:broadcom:spring_batch:6.0.1
-
cpe:2.3:a:broadcom:spring_batch:6.0.2
-
cpe:2.3:a:broadcom:spring_batch:6.0.3
-
cpe:2.3:a:broadcom:spring_batch:6.0.4