CVE-2026-47861

Updated on 27 Aug 2026

Severity

4.0 Medium severity

Details

CVSS score
4.0
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Overview

About vulnerability

An unauthenticated remote attacker who can send a single UDP packet to a Spring Integration UDP inbound adapter can cause the server to emit an outbound UDP datagram to an arbitrary internal or external host and port of the attacker’s choosing. This enables blind UDP SSRF (port scanning of internal networks via ICMP/behavior timing, triggering UDP services such as memcached/SNMP/NTP on internal hosts, or using the server as a reflection hop). The attacker controls both host and port; the payload is a 36-byte UUID string.

Details

Affected product:
Apache Log4j , Spring , camel
Affected packages:
Spring Boot @ 2.6.15 (+2675 more)