MEDIUM 6.5 Maven
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
GHSA-xvfq-4q6q-gxx7 · CVE-2026-41726
Published · Modified
Description
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.
Affected versions:
Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-41726
- WEB https://github.com/spring-projects/spring-kafka/issues/4489
- WEB https://github.com/spring-projects/spring-kafka/commit/ca2337ba789c5778a10197bda17a62915247ff6c
- PACKAGE https://github.com/spring-projects/spring-kafka
- WEB https://spring.io/security/cve-2026-41726
Ready to move
Start Securing
Free, no credit card | First findings in minutes