VMware

Spring For Apache Kafka

6 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.37%
  • Veröffentlicht 27.08.2026 18:04:46
  • Zuletzt bearbeitet 04.09.2026 19:21:37

DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation. Spring for Apache Kafka 4.1.0...

  • EPSS 0.16%
  • Veröffentlicht 27.08.2026 06:17:22
  • Zuletzt bearbeitet 01.09.2026 16:07:35

JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer can inject a ja...

  • EPSS 0.51%
  • Veröffentlicht 09.06.2026 23:49:26
  • Zuletzt bearbeitet 05.08.2026 13:22:14

JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean de...

  • EPSS 0.24%
  • Veröffentlicht 09.06.2026 23:49:10
  • Zuletzt bearbeitet 23.07.2026 09:10:00

Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause t...

  • EPSS 0.3%
  • Veröffentlicht 09.06.2026 23:48:51
  • Zuletzt bearbeitet 23.07.2026 09:10:00

When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. A...

  • EPSS 2.18%
  • Veröffentlicht 24.08.2023 13:15:07
  • Zuletzt bearbeitet 21.11.2024 08:06:27

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of...