6.5
CVE-2026-59278
- EPSS 0.16%
- Veröffentlicht 27.08.2026 06:17:22
- Zuletzt bearbeitet 01.09.2026 16:07:35
- Erkennungen
In Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted java.net types in header mapper default trusted packages
JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer can inject a java.net.InetAddress type via the spring_json_header_types message header. Spring for Apache Kafka 4.1.0 Spring for Apache Kafka 4.0.0 - 4.0.6 Spring for Apache Kafka 3.0.0 - 3.3.16 Spring for Apache Kafka 2.9.0 - 2.9.14 Spring for Apache Kafka 2.8.12 and earlier
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Spring For Apache Kafka Version < 2.8.13
VMware ≫ Spring For Apache Kafka Version >= 2.9.0 < 2.9.15
VMware ≫ Spring For Apache Kafka Version >= 3.0.0 < 3.3.17
VMware ≫ Spring For Apache Kafka Version >= 4.0.0 < 4.0.6.1
VMware ≫ Spring For Apache Kafka Version >= 4.1.0 < 4.1.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.16% | 0.054 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| VMware | 6.5 | 3.9 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
|
CWE-918 Server-Side Request Forgery (SSRF)
The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.
https://spring.io/security/cve-2026-59278