---
title: "fluxTransform shared RequestMessageHolder causes cross-message header leakage under async fluxFunction"
url: https://daily.dev/posts/fluxtransform-shared-requestmessageholder-causes-cross-message-header-leakage-under-async-fluxfuncti-lrwzjof0i
source_url: https://spring.io/security/cve-2026-59324
type: article
source: "Spring"
published: 2026-08-20T16:42:37.955Z
updated: 2026-08-20T16:42:56.749Z
tags: ["security", "java", "spring"]
reading_time: 1
upvotes: 1
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# fluxTransform shared RequestMessageHolder causes cross-message header leakage under async fluxFunction

**[Spring](https://daily.dev/sources/spring)** · 1 min read · 1 upvotes · 0 comments

## Summary

A CVE advisory page references a vulnerability titled 'fluxTransform shared RequestMessageHolder causes cross-message header leakage under async fluxFunction', but the actual content of the page consists only of a cookie consent notice with no technical details about the vulnerability, affected versions, or remediation.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://spring.io/security/cve-2026-59324>

## Similar posts on daily.dev

- [Unsafe Java deserialization in SerializingHttpMessageConverter — remote code execution](https://daily.dev/posts/unsafe-java-deserialization-in-serializinghttpmessageconverter-remote-code-execution-wisjbrluv) · Spring · 7 upvotes · 0 comments
- [JsonToObjectTransformer resolves the json\_\_TypeId\_\_ message header to an arbitrary class without an allow-list](https://daily.dev/posts/jsontoobjecttransformer-resolves-the-json-typeid-message-header-to-an-arbitrary-class-without-an--pnqdqqjdm) · Spring · 2 upvotes · 0 comments
- [EmbeddedHeadersJsonMessageMapper default gives wire peer full control of MessageHeaders](https://daily.dev/posts/embeddedheadersjsonmessagemapper-default-gives-wire-peer-full-control-of-messageheaders-pxcmbfa2r) · Spring · 3 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#java](https://daily.dev/tags/java), [#spring](https://daily.dev/tags/spring)

[View this post on daily.dev](https://daily.dev/posts/fluxtransform-shared-requestmessageholder-causes-cross-message-header-leakage-under-async-fluxfuncti-lrwzjof0i)
