{"id":"CVE-2026-47888","title":"A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 -…","summary":"A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 -…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-401"],"vendor":"vmware","product":"spring_framework","affected":["spring_framework >= 5.2.0, < 5.2.26","spring_framework >= 5.3.0, < 5.3.50","spring_framework >= 6.0.0, < 6.0.31","spring_framework >= 6.1.0, < 6.1.29","spring_framework >= 6.2.0, < 6.2.20","spring_framework >= 7.0.0, < 7.0.8.1"],"patched":["spring_framework 7.0.8.1"],"published":"2026-08-27","updated":"2026-09-10","sourceUpdated":"2026-09-10T14:26:40.220","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-47888","references":[{"url":"https://spring.io/security/cve-2026-47888","label":"security@vmware.com"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47888.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-47888"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2524860"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-47888"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-47888"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.00324,"epssPercentile":0.25665,"ingestedAt":"2026-09-10T14:51:56.240Z","slug":"CVE-2026-47888","body":"## Overview\n\nA Spring RSocket application is exposed to a memory leak via a malformed SETUP frame.\nSpring Framework 7.0.0 - 7.0.8\nSpring Framework 6.2.0 - 6.2.19\nSpring Framework 6.1.0 - 6.1.28\nSpring Framework 6.0.0 - 6.0.30\nSpring Framework 5.3.0 - 5.3.49\nSpring Framework 5.2.0.RELEASE - 5.2.25.RELEASE\n\n## Affected\n\n- `spring_framework >= 5.2.0, < 5.2.26`\n- `spring_framework >= 5.3.0, < 5.3.50`\n- `spring_framework >= 6.0.0, < 6.0.31`\n- `spring_framework >= 6.1.0, < 6.1.29`\n- `spring_framework >= 6.2.0, < 6.2.20`\n- `spring_framework >= 7.0.0, < 7.0.8.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `spring_framework 7.0.8.1`\n\n## Vendor advisories\n\n- **Red Hat VEX** · Important · affected: Exploit Intelligence, OpenShift Developer Tools and Services, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, Red Hat build of Quarkus, Red Hat Enterprise Linux 10, … · no fix planned: Exploit Intelligence, OpenShift Developer Tools and Services, Red Hat build of Apache Camel - HawtIO 4, Red Hat build of Apache Camel 4 for Quarkus 3, … · updated 2026-09-18 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-47888.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}