CVE-2026-47859
5.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Summary
RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frames, trusts the sender-supplied octet count of an octet-counted frame and allocates a byte array of exactly that size with no upper bound. Spring Integration 7.1.0 Spring Integration 7.0.0 - 7.0.5 Spring Integration 6.5.0 - 6.5.10 Spring Integration 6.4.0 - 6.4.12 Spring Integration 5.5.21 and earlier
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Spring | Spring Integration | 7.1.0 | affected |
| Spring | Spring Integration | 7.0.0 <= 7.0.5 | affected |
| Spring | Spring Integration | 6.5.0 <= 6.5.10 | affected |
| Spring | Spring Integration | 6.4.0 <= 6.4.12 | affected |
| Spring | Spring Integration | 0 <= 5.5.21 | affected |
Weaknesses
- CWE-770 Allocation of Resources Without Limits or Throttling
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.