Deserialization Flaw in Spring Integration by VMware
CVE-2026-47859

5.4MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
26 August 2026

What is CVE-2026-47859?

The vulnerability arises in the RFC6587SyslogDeserializer component within the Spring Integration syslog TCP inbound adapter. This component fails to properly validate the sender-supplied octet count of incoming octet-counted frames, leading to uncontrolled memory allocation of byte arrays. This flaw could be exploited by an attacker to craft malicious syslog messages, potentially leading to Denial of Service (DoS) or other unpredicted behaviors in applications using affected versions of Spring Integration.

Affected Version(s)

Spring Integration 7.1.0

Spring Integration 7.0.0 <= 7.0.5

Spring Integration 6.5.0 <= 6.5.10

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.