Known Vulnerabilities for Spring For Apache Kafka by Vmware
Listed below are 6 of the newest known vulnerabilities associated with "Spring For Apache Kafka" by "Vmware".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-59317 json | DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passe... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-59278 json | JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mapper... | Not Provided | 2026-08-27 | 2026-08-27 |
| CVE-2026-41731 json | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefi... | Not Provided | 2026-06-10 | 2026-08-05 |
| CVE-2026-41727 json | Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. ... | Not Provided | 2026-06-10 | 2026-06-27 |
| CVE-2026-41726 json | When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending record... | Not Provided | 2026-06-10 | 2026-06-27 |
| CVE-2023-34040 json | In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existe... | 7.8 - HIGH | 2023-08-24 | 2023-10-18 |