← Vulnerability feed

Vulnerability record · CVE-2026-41727 · published 10 June 2026

CVE-2026-41727: Vmware spring for apache kafka improper input validation vulnerability

Vmware · Spring For Apache Kafka

Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause the retry topic router to misidentify where the message was in the retry sequence. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.

6.5 CVSS 3.1 Medium EPSS 0.42% · top 66.1% CWE-20 · Improper input validation
6.5CVSS 3.1 base score
0.42%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
23 Jul 2026Last modified by NVD

Description

Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause the retry topic router to misidentify where the message was in the retry sequence. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-41727 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.1CVE-2026-41731Vmware spring for apache kafka deserialization of untrusted data vulnerabilityJsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that tr…EPSS 0.65%7.8CVE-2023-34040Vmware spring for apache kafka deserialization of untrusted data vulnerabilityIn Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual c…EPSS 2.1%6.5CVE-2026-59317Vmware spring for apache kafka vulnerabilityDeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly…EPSS 0.42%6.5CVE-2026-59278Vmware spring for apache kafka server-side request forgery (ssrf) vulnerabilityJsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is th…EPSS 0.27%6.5CVE-2026-41726Vmware spring for apache kafka allocation without limits vulnerabilityWhen an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spr…EPSS 0.42%9.5CVE-2026-88771Citrix netscaler application delivery controller improper input validation vulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEVEPSS 1.1%9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 1.1%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed

Source: NIST National Vulnerability Database (record CVE-2026-41727), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.