org.springframework.kafka:spring-kafka vulnerabilities
CVEs whose affected-version data names the org.springframework.kafka:spring-kafka package (maven). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-41731High· 8.1In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
▾ Twilightspringframework · org.springframework.kafka:spring-kafkaEPSS 0.51%via GHSA
CVE-2026-41726Medium· 6.5In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
▾ Sunlitspringframework · org.springframework.kafka:spring-kafkaEPSS 0.30%via GHSA