8.1
CVE-2026-41731
- EPSS 0.51%
- Veröffentlicht 09.06.2026 23:49:26
- Zuletzt bearbeitet 05.08.2026 13:22:14
- Erkennungen
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that caused the consumer to deserialize arbitrary JDK types. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring For Apache Kafka Version >= 2.8.0 < 2.8.12
VMware ≫ Spring For Apache Kafka Version >= 2.9.0 < 2.9.14
VMware ≫ Spring For Apache Kafka Version >= 3.2.0 < 3.2.14
VMware ≫ Spring For Apache Kafka Version >= 3.3.0 < 3.3.15.1
VMware ≫ Spring For Apache Kafka Version >= 4.0.0 < 4.0.5.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.51% | 0.401 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| VMware | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| 0b0ca135-0b70-47e7-9f44-1890c2a1c46c | 8.1 | 2.2 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-502 Deserialization of Untrusted Data
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
https://spring.io/security/cve-2026-41731
https://bugzilla.redhat.com/show_bug.cgi?id=2487375
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41731.json
https://access.redhat.com/security/cve/CVE-2026-41731