Vmware · Spring Integration · CVE-2026-47859
**Name of the Vulnerable Software and Affected Versions**
Spring Integration versions 7.0.0 through 7.0.5
Spring Integration versions 6.5.0 through 6.5.10
Spring Integration versions 6.4.0 through 6.4.12
Spring Integration versions 5.5.x and earlier
Spring Integration version 7.1.0
**Description**
The `RFC6587SyslogDeserializer`, utilized by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 and RFC 5424 frames, contains a flaw where it trusts the octet count provided by the sender. This allows the system to allocate a byte array of the specified size without an upper bound, potentially leading to a heap overflow (a condition where a program writes more data to a heap-allocated memory block than it can hold).
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.