Impact
A malformed SETUP frame sent to the RSocketMessageHandler in Spring Framework creates a memory leak that allows an attacker to gradually exhaust heap space, potentially causing out‑of‑memory exceptions and preventing the application from serving requests. This vulnerability does not provide direct code execution but can degrade availability and, in some environments, trigger cascading failures. The memory leak arises from improper handling of malformed payloads during RSocket protocol initialization.
Affected Systems
Spring Framework versions 5.2.0.RELEASE through 5.2.25.RELEASE, 5.3.0 through 5.3.49, 6.0.0 through 6.0.30, 6.1.0 through 6.1.28, 6.2.0 through 6.2.19, and 7.0.0 through 7.0.8 are affected.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but resource exhaustion can be exploited via a remote attacker who can send crafted RSocket messages to the application. Without a patch, repeated use of the malformed SETUP frame can lead to service interruption. No CVSS score is provided, so assess severity based on the potential for availability loss; the risk remains significant due to the lack of mitigation in the affected releases.
OpenCVE Enrichment