VendorsVMwarespring_for_apache_kafkaany version
Vulnerabilities

VMware Spring for Apache Kafka any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2026-41731
In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
Published 2026-06-09 · Analyzed
8.1EPSS 0.005
CVE-2023-34040
Java Deserialization vulnerability in Spring-Kafka When Improperly Configured
Published 2023-08-24 · Modified
7.8EPSS 0.021
CVE-2026-59317
In Spring for Apache Kafka, missing header validation in DeadLetterPublishingRecovererFactory enables denial of service via a poison-pill loop
Published 2026-08-27 · Analyzed
6.5EPSS 0.004
CVE-2026-41726
In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header
Published 2026-06-09 · Analyzed
6.5EPSS 0.003
CVE-2026-41727
In Spring for Apache Kafka, forged retry topic headers subvert retry routing and backoff behavior
Published 2026-06-09 · Analyzed
6.5EPSS 0.002
CVE-2026-59278
In Spring for Apache Kafka, SSRF via DNS resolution triggered by untrusted java.net types in header mapper default trusted packages
Published 2026-08-27 · Analyzed
6.5EPSS 0.002