CVE-2026-59317
- EPSS 0.37%
- Veröffentlicht 27.08.2026 18:04:46
- Zuletzt bearbeitet 04.09.2026 19:21:37
DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation. Spring for Apache Kafka 4.1.0...
CVE-2026-59278
- EPSS 0.16%
- Veröffentlicht 27.08.2026 06:17:22
- Zuletzt bearbeitet 01.09.2026 16:07:35
JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer can inject a ja...
CVE-2026-41731
- EPSS 0.51%
- Veröffentlicht 09.06.2026 23:49:26
- Zuletzt bearbeitet 05.08.2026 13:22:14
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean de...
CVE-2026-41727
- EPSS 0.24%
- Veröffentlicht 09.06.2026 23:49:10
- Zuletzt bearbeitet 23.07.2026 09:10:00
Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause t...
CVE-2026-41726
- EPSS 0.3%
- Veröffentlicht 09.06.2026 23:48:51
- Zuletzt bearbeitet 23.07.2026 09:10:00
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. A...
CVE-2023-34040
- EPSS 2.18%
- Veröffentlicht 24.08.2023 13:15:07
- Zuletzt bearbeitet 21.11.2024 08:06:27
In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of...