CVE-2026-41726Medium· 6.5▾ SunlitIn Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
▾ Sunlit zone — Low / medium · no exploitation signal
impact 35.8 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
0.3%
0.3% → 0.3%
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.
Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
org.springframework.kafka:spring-kafka >= 4.0.0, <= 4.0.5org.springframework.kafka:spring-kafka >= 3.3.0, <= 3.3.15org.springframework.kafka:spring-kafka >= 3.2.0, <= 3.2.13org.springframework.kafka:spring-kafka >= 2.9.0, <= 2.9.13org.springframework.kafka:spring-kafka <= 2.8.11Upgrade to a patched release:
org.springframework.kafka:spring-kafka 4.0.6org.springframework.kafka:spring-kafka 3.3.16Connected by shared product, vendor, weakness, or advisory.
CVE-2026-41731High· 8.1In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
CVE-2026-16100Medium· 6.5A flaw was found in the user-event metrics recording of Keycloak
CVE-2025-11362High· 7.5Versions of the package pdfmake from 0.3.0-beta.1 and before 0.3.0-beta.17 are vulnerable to Allocation of Resources Without Limits or Throttling via repeatedly redirect URL in file embedding
CVE-2023-5379High· 7.5A flaw was found in Undertow
CVE-2024-12254High· 7.5Starting in Python 3.12.0, the asyncio._SelectorSocketTransport.writelines() method would not "pause" writing and signal to the Protocol to drain the buffer to the wire once the write buffer reached the "high-water mark"
CVE-2026-47838Medium· 6.8Spring Security Vulnerable to Unauthorized User Impersonation when Using X.509 Client Certificates