THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-59324 (HIGH 8.2) — When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant

[NVD] CVE-2026-59324 (HIGH 8.2) — When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant

mednvdPublished 2026-08-27

CVE-2026-59324 CVSS: 8.2 HIGH Published: 2026-08-27T20:17:58.500

When an IntegrationFlow uses .fluxTransform() with an asynchronous/reordering fluxFunction that emits raw payloads, concurrent requests on the same FluxMessageChannel subscription have their reply headers (replyChannel, errorChannel, correlationId, any propagated security/tenant headers) copied from whichever message was most recent

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-59324