Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41726

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 6.5

Описание

When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.

A flaw was found in spring-kafka. When an application uses the DelegatingDeserializer, a malicious producer can exploit this vulnerability by sending records with unique, random spring.kafka.serialization.selector header values. This can cause the consumer's memory (heap) to grow without limits, leading to excessive garbage collection activity and eventually an OutOfMemoryError, resulting in a Denial of Service (DoS) for the application.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Fuse 7spring-kafkaFix deferred
Red Hat JBoss Enterprise Application Platform Expansion Packspring-kafkaFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2487380spring-kafka: Spring-kafka: Denial of Service due to unbounded heap growth via unique header values

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
около 2 месяцев назад

When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.

CVSS3: 6.5
github
около 2 месяцев назад

In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header

6.5 Medium

CVSS3