Input validation error in Spring Integration - CVE-2026-47859
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in RFC6587SyslogDeserializer when processing octet-counted RFC 6587 / RFC 5424 frames. A remote user can send a frame with an arbitrarily large declared length to cause a denial of service.
The non-transparent LF-delimited framing path is not affected.
Affected software
Library Support for Spring
How to mitigate CVE-2026-47859
Library Support for Spring - update to 3.5.19