spring-messaging is vulnerable to Denial of Service (DoS)
43
Medium Risk
spring-messaging RSocketMessageHandler leaks memory when processing a malformed SETUP frame. A connected peer can repeat such frames and grow retained objects without bound. That degrades or exhausts the RSocket server. The patch releases SETUP-frame state on invalid input.
You are affected if you are using a version that falls within the vulnerable range and the application handles RSocket SETUP frames through RSocketMessageHandler.
spring-messaging is vulnerable to Denial of Service (DoS) in versions 5.2.0 - 7.0.8.
Upgrade the org.springframework:spring-messaging library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant