PT-2026-48327 · Vmware · Spring For Apache Kafka

·

CVE-2026-41731

·

Published

2026-06-09

·

Updated

2026-08-05

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Spring for Apache Kafka versions 4.0.0 through 4.0.5 Spring for Apache Kafka versions 3.3.0 through 3.3.15 Spring for Apache Kafka versions 3.2.0 through 3.2.13 Spring for Apache Kafka versions 2.9.0 through 2.9.13 Spring for Apache Kafka versions 2.8.0 through 2.8.11
Description JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper use a prefix check to match type headers against trusted packages. This mechanism causes any trusted package to implicitly trust all of its subpackages. When combined with Jackson's default bean deserialization, a producer can provide crafted header values that lead the consumer to deserialize arbitrary JDK types.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41731
GHSA-XQ69-5H5V-X9X4

Affected Products

Spring For Apache Kafka