A security advisory describes a remote denial-of-service vulnerability in Spring's RFC6587SyslogDeserializer, where octet-counted framing parsing can trigger unbounded memory allocation, allowing an attacker to exhaust memory resources. No further technical details, affected version ranges, or remediation guidance are visible beyond the advisory title and a cookie consent notice.
Questions this post answers
What is the vulnerability in Spring's RFC6587SyslogDeserializer related to octet-counted framing?
RFC6587SyslogDeserializer in Spring is affected by an unbounded memory allocation issue when parsing octet-counted framing, which can be exploited remotely to cause a denial of service by exhausting available memory. Specific affected version numbers and a patched release are not detailed beyond the advisory title itself. Track Spring CVE advisories like this one on daily.dev before they hit production syslog pipelines.