THREAT OPS › Threat News › [NVD] CVE-2026-59324 (HIGH 8.2) — When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant
[NVD] CVE-2026-59324 (HIGH 8.2) — When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant
CVE-2026-59324 CVSS: 8.2 HIGH Published: 2026-08-27T20:17:58.500
When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message was most recent
Indicators of compromise
- CVE-2026-59324cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-59324