← Vulnerability feed

Vulnerability record · CVE-2023-34040 · published 24 August 2023

CVE-2023-34040: Vmware spring for apache kafka deserialization of untrusted data vulnerability

Vmware · Spring For Apache Kafka

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an application is vulnerable when all of the following are true: * The user does not configure an ErrorHandlingDeserializer for the key and/or value of the record * The user explicitly sets container properties checkDeserExWhenKeyNull and/or checkDeserExWhenValueNull container properties to true. * The user allows untrusted sources to publish to a Kafka topic By default, these properties are false, and the container only attempts to deserialize the headers if an ErrorHandlingDeserializer is configured. The ErrorHandlingDeserializer prevents the vulnerability by removing any such malicious headers before processing the record.

7.8 CVSS 3.1 High EPSS 2.1% · top 19.1% CWE-502 · Deserialization of untrusted data
7.8CVSS 3.1 base score
2.1%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an application is vulnerable when all of the following are true: * The user does not configure an ErrorHandlingDeserializer for the key and/or value of the record * The user explicitly sets container properties checkDeserExWhenKeyNull and/or checkDeserExWhenValueNull container properties to true. * The user allows untrusted sources to publish to a Kafka topic By default, these properties are false, and the container only attempts to deserialize the headers if an ErrorHandlingDeserializer is configured. The ErrorHandlingDeserializer prevents the vulnerability by removing any such malicious headers before processing the record.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://spring.io/security/cve-2023-34040 MitigationVendor Advisory
https://spring.io/security/cve-2023-34040 MitigationVendor Advisory

Track CVE-2023-34040 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2026-41731Vmware spring for apache kafka deserialization of untrusted data vulnerabilityJsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that tr…EPSS 0.65%6.5CVE-2026-59317Vmware spring for apache kafka vulnerabilityDeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly…EPSS 0.42%6.5CVE-2026-59278Vmware spring for apache kafka server-side request forgery (ssrf) vulnerabilityJsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is th…EPSS 0.27%6.5CVE-2026-41726Vmware spring for apache kafka allocation without limits vulnerabilityWhen an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spr…EPSS 0.42%6.5CVE-2026-41727Vmware spring for apache kafka improper input validation vulnerabilitySpring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a …EPSS 0.42%9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 90%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed

Source: NIST National Vulnerability Database (record CVE-2023-34040), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.