Affected versions:
Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xvfq-4q6q-gxx7 | In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header |
Fri, 12 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Wed, 10 Jun 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 10 Jun 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Spring
Spring spring For Apache Kafka Vmware Vmware spring For Apache Kafka |
|
| Vendors & Products |
Spring
Spring spring For Apache Kafka Vmware Vmware spring For Apache Kafka |
Wed, 10 Jun 2026 00:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11. | |
| Title | In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: vmware
Published:
Updated: 2026-06-27T21:14:56.775Z
Reserved: 2026-04-22T06:21:39.014Z
Link: CVE-2026-41726
Updated: 2026-06-10T17:40:11.443Z
Status : Awaiting Analysis
Published: 2026-06-10T00:16:52.030
Modified: 2026-06-10T19:24:04.320
Link: CVE-2026-41726
OpenCVE Enrichment
Updated: 2026-06-10T11:21:37Z
Github GHSA