← Vulnerability feed

Vulnerability record · CVE-2026-41726 · published 10 June 2026

CVE-2026-41726: Vmware spring for apache kafka allocation without limits vulnerability

Vmware · Spring For Apache Kafka

When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.

6.5 CVSS 3.1 Medium EPSS 0.42% · top 66.1% CWE-770 · Allocation without limits
6.5CVSS 3.1 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
23 Jul 2026Last modified by NVD

Description

When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-41726 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2026-41731Vmware spring for apache kafka deserialization of untrusted data vulnerabilityJsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that tr…EPSS 0.65%7.8CVE-2023-34040Vmware spring for apache kafka deserialization of untrusted data vulnerabilityIn Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual c…EPSS 2.1%6.5CVE-2026-59317Vmware spring for apache kafka vulnerabilityDeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly…EPSS 0.42%6.5CVE-2026-59278Vmware spring for apache kafka server-side request forgery (ssrf) vulnerabilityJsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is th…EPSS 0.27%6.5CVE-2026-41727Vmware spring for apache kafka improper input validation vulnerabilitySpring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a …EPSS 0.42%8.6CVE-2020-3569Cisco IOS XR DVMRP IGMP packet handling memory exhaustionCisco IOS XR Software mishandles IGMP packets in its Distance Vector Multicast Routing Protocol (DVMRP) feature, allowing crafted traffic to crash th…KEVEPSS 3.3%analysed8.6CVE-2020-3566Cisco IOS XR DVMRP IGMP queue flaw causes memory exhaustionCisco IOS XR Software mishandles queue management for IGMP packets in its DVMRP feature, allowing uncontrolled memory consumption. An unauthenticated…KEVEPSS 3.7%analysed

Source: NIST National Vulnerability Database (record CVE-2026-41726), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.