SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-47888

HIGH · CVSS 7.5 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-27 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Spring Framework versions 5.2.x through 7.0.x are vulnerable to a memory leak triggered by a malformed SETUP frame in RSocket applications. This vulnerability can lead to increased memory consumption, potentially degrading application performance or causing outages. Organizations utilizing affected Spring Framework versions should prioritize remediation to mitigate risks associated with resource exhaustion.

CVE
CVE-2026-47888
Severity
HIGH
CVSS
7.5
EPSS
0.32%

Original NVD Description

A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE

Related CVEs

Other vulnerabilities affecting the same vendor(s)