A Spring RSocket application is exposed to a memory leak via a malformed SETUP frame. Spring Framework 7.0.0 - 7.0.8 Spring Framework 6.2.0 - 6.2.19 Spring Framework 6.1.0 - 6.1.28 Spring Framework 6.0.0 - 6.0.30 Spring Framework 5.3.0 - 5.3.49 Spring Framework 5.2.0.RELEASE - 5.2.25.RELEASE
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-47888 is a memory leak vulnerability affecting multiple versions of the Spring Framework across a wide range of releases (5.2 through 7.0). The vulnerability is triggered when a Spring RSocket application receives a specially crafted SETUP frame, causing improper resource management that leads to memory exhaustion over time. RSocket is a binary protocol for reactive communication, commonly used in microservices architectures and cloud-native applications. With a CVSS score of 7.5, this vulnerability poses a significant availability risk—attackers can send malformed frames to cause denial of service through memory depletion, impacting any organization running vulnerable Spring Framework versions in RSocket-enabled deployments.
While this CVE does not map directly to MITRE ATT&CK techniques, Casky's AI-driven skills excel at detecting the underlying attack patterns through behavioral analysis of resource consumption and protocol anomalies. Practitioners using Casky would observe findings related to CWE-401 (improper resource cleanup) manifesting as: abnormal memory growth correlating with RSocket SETUP frame traffic, orphaned connection objects that fail to release allocated buffers, and statistical deviations in frame processing latency. Claude's extended reasoning capabilities enable Casky to correlate these signals—recognizing that legitimate RSocket handshakes follow predictable memory profiles, while malformed frames trigger characteristic allocation patterns that deviate from baseline behavior. Practitioners would see alerts highlighting suspicious SETUP frame characteristics, memory allocation spikes tied to specific connection patterns, and recommendations to update to patched versions (7.0.9+, 6.2.20+, 6.1.29+, 6.0.31+, or 5.3.50+).
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-47888. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation