Impact
A malformed SETUP frame sent to the RSocketMessageHandler in Spring Framework creates a memory leak that allows an attacker to gradually exhaust heap space, potentially causing out-of-memory exceptions and preventing the application from serving requests. Although it does not provide code execution, the lack of proper handling leads to significant denial of service, and the CVSS score of 7.5 highlights the severe availability impact.
Affected Systems
Spring Framework versions 5.2.0.RELEASE through 5.2.25.RELEASE, 5.3.0 through 5.3.49, 6.0.0 through 6.0.30, 6.1.0 through 6.1.28, 6.2.0 through 6.2.19, and 7.0.0 through 7.0.8 are affected.
Risk and Exploitability
EPSS score is less than 1%, suggesting widespread exploitation is unlikely at present, but the low probability does not eliminate risk. The CVSS score of 7.5 indicates a high severity due to availability impact, and the vulnerability is not listed in CISA KEV, meaning no known active exploit. The likely attack vector is remote over the network via crafted RSocket messages. Without a patch, repeated receipt of malformed SETUP frames can deplete server memory, leading to denial of service.
OpenCVE Enrichment