CVE-2026-41731
published 2026-06-10CVE-2026-41731: JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any…
PriorityP350high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
0.49%
38.9th percentile
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that caused the consumer to deserialize arbitrary JDK types.
Affected versions:
Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | fuse | — | — |
| spring | spring_for_apache_kafka | >= 2.8.0 < 2.8.12 | 2.8.12 |
| spring | spring_for_apache_kafka | >= 2.9.0 < 2.9.14 | 2.9.14 |
| spring | spring_for_apache_kafka | >= 3.2.0 < 3.2.14 | 3.2.14 |
| spring | spring_for_apache_kafka | >= 3.3.0 < 3.3.15.1 | 3.3.15.1 |
| spring | spring_for_apache_kafka | >= 4.0.0 < 4.0.5.1 | 4.0.5.1 |
| vmware | spring_for_apache_kafka | >= 2.8.0 < 2.8.12 | 2.8.12 |
| vmware | spring_for_apache_kafka | >= 2.9.0 < 2.9.14 | 2.9.14 |
| vmware | spring_for_apache_kafka | >= 3.2.0 < 3.2.14 | 3.2.14 |
| vmware | spring_for_apache_kafka | >= 3.3.0 < 3.3.15.1 | 3.3.15.1 |
| vmware | spring_for_apache_kafka | >= 4.0.0 < 4.0.5.1 | 4.0.5.1 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
spring-kafka: Spring for Apache Kafka: Arbitrary code execution via insecure deserialization of crafted header values
vendor_redhat·2026-06-09·CVSS 8.1
CVE-2026-41731 [HIGH] CWE-502 spring-kafka: Spring for Apache Kafka: Arbitrary code execution via insecure deserialization of crafted header values
spring-kafka: Spring for Apache Kafka: Arbitrary code execution via insecure deserialization of crafted header values
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that caused the consumer to deserialize arbitrary JDK types.
Affected versions:
Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
A flaw was found in the spring-kafka component. A remote attacker, by supplying crafted header values, could exploit a vulnerability in JsonKafkaHeaderMappe
GHSA
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
ghsa·2026-06-10
CVE-2026-41731 [HIGH] CWE-502 In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that caused the consumer to deserialize arbitrary JDK types.
Affected versions:
Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
GHSA
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its su
ghsa_unreviewed·2026-06-10
CVE-2026-41731 [HIGH] CWE-502 JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its su
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that caused the consumer to deserialize arbitrary JDK types.
Affected versions:
Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
No detection rules found.
No public exploits indexed.
2026-06-10
Published