Deserialization Flaw in Spring Integration by VMware
CVE-2026-47859
5.4MEDIUM
What is CVE-2026-47859?
The vulnerability arises in the RFC6587SyslogDeserializer component within the Spring Integration syslog TCP inbound adapter. This component fails to properly validate the sender-supplied octet count of incoming octet-counted frames, leading to uncontrolled memory allocation of byte arrays. This flaw could be exploited by an attacker to craft malicious syslog messages, potentially leading to Denial of Service (DoS) or other unpredicted behaviors in applications using affected versions of Spring Integration.
Affected Version(s)
Spring Integration 7.1.0
Spring Integration 7.0.0 <= 7.0.5
Spring Integration 6.5.0 <= 6.5.10
