cbcvebase.

Spring For Apache Kafka vulnerabilities

4 known vulnerabilities affecting spring/spring_for_apache_kafka.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2026-41731P3HIGHCVSS 8.1≥ 4.0.0, < 4.0.5.1≥ 3.3.0, < 3.3.15.1+3 more2026-06-10
CVE-2026-41731 [HIGH] CWE-502 CVE-2026-41731: JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trust JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that caused the consumer to deserialize ar
nvd
CVE-2023-34040P3HIGHCVSS 7.8≥ 2.8.x, < 2.9.11≥ 2.9.x, < 2.9.11+1 more2023-08-24
CVE-2023-34040 [HIGH] CWE-502 CVE-2023-34040: In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserializa In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an application is vulnerable when all of
nvd
CVE-2026-41726P3MEDIUMCVSS 6.5≥ 4.0.0, < 4.0.5.1≥ 3.3.0, < 3.3.15.1+3 more2026-06-10
CVE-2026-41726 [MEDIUM] CWE-770 CVE-2026-41726: When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap withou When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.
nvd
CVE-2026-41727P3MEDIUMCVSS 6.5≥ 4.0.0, < 4.0.5.1≥ 3.3.0, < 3.3.15.1+3 more2026-06-10
CVE-2026-41727 [MEDIUM] CWE-20 CVE-2026-41727: Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header value Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause the retry topic router to misidentify where the message was in the retry sequence. Affected versions:
nvd
Spring For Apache Kafka vulnerabilities | cvebase