CVE-2026-41726
published 2026-06-10CVE-2026-41726: When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random…
PriorityP337medium6.5CVSS 3.1
AVNACLPRLUINSUCNINAH
EPSS
0.29%
20.9th percentile
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.
Affected versions:
Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| spring | spring_for_apache_kafka | >= 2.8.0 < 2.8.12 | 2.8.12 |
| spring | spring_for_apache_kafka | >= 2.9.0 < 2.9.14 | 2.9.14 |
| spring | spring_for_apache_kafka | >= 3.2.0 < 3.2.14 | 3.2.14 |
| spring | spring_for_apache_kafka | >= 3.3.0 < 3.3.15.1 | 3.3.15.1 |
| spring | spring_for_apache_kafka | >= 4.0.0 < 4.0.5.1 | 4.0.5.1 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
ghsa·2026-06-10
CVE-2026-41726 [MEDIUM] CWE-770 In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.
Affected versions:
Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
GHSA
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eve
ghsa_unreviewed·2026-06-10
CVE-2026-41726 [MEDIUM] CWE-770 When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eve
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.
Affected versions:
Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
Red Hat
spring-kafka: Spring-kafka: Denial of Service due to unbounded heap growth via unique header values
vendor_redhat·2026-06-09·CVSS 6.5
CVE-2026-41726 [MEDIUM] CWE-770 spring-kafka: Spring-kafka: Denial of Service due to unbounded heap growth via unique header values
spring-kafka: Spring-kafka: Denial of Service due to unbounded heap growth via unique header values
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.
Affected versions:
Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
A flaw was found in spring-kafka. When an application uses the DelegatingDeserializer, a malicious producer can exploit this vulnerability by sending records with unique, random `spring.kafka.serialization.selector` header values. This can cause the consumer's memory (heap) to grow without limits,
No detection rules found.
No public exploits indexed.
2026-06-10
Published