Vmware Spring For Apache Kafka vulnerabilities
4 known vulnerabilities affecting vmware/spring_for_apache_kafka.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2026-41731P3HIGHCVSS 8.1≥ 2.8.0, < 2.8.12≥ 2.9.0, < 2.9.14+3 more2026-06-10
CVE-2026-41731 [HIGH] CWE-502 CVE-2026-41731: JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trust
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that caused the consumer to deserialize ar
nvd
CVE-2023-34040P3HIGHCVSS 7.8≥ 2.8.1, ≤ 2.9.10≥ 3.0.0, ≤ 3.0.92023-08-24
CVE-2023-34040 [HIGH] CWE-502 CVE-2023-34040: In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserializa
In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers.
Specifically, an application is vulnerable when all of
nvd
CVE-2026-41726P3MEDIUMCVSS 6.5fixed in 2.8.12≥ 2.9.0, < 2.9.14+3 more2026-06-10
CVE-2026-41726 [MEDIUM] CWE-770 CVE-2026-41726: When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap withou
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.
Affected versions:
Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.
nvd
CVE-2026-41727P3MEDIUMCVSS 6.5≥ 2.8.0, < 2.8.12≥ 2.9.0, < 2.9.14+3 more2026-06-10
CVE-2026-41727 [MEDIUM] CWE-20 CVE-2026-41727: Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header value
Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause the retry topic router to misidentify where the message was in the retry sequence.
Affected versions:
nvd