Skip to content
CVE-2026-41726: Heap Growth Vulnerability in Spring for Apache Kafka

CVE-2026-41726: Heap Growth Vulnerability in Spring for Apache Kafka

First seen 10 Jun 2026, 09:30 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster June 11, 2026 at 09:28 UTC
  • CVE-2026-41726 allows heap growth leading to OutOfMemoryError in specific Spring versions.
  • Affected versions include Spring for Apache Kafka 4.0.0 to 4.0.5 and earlier versions.
  • Users are urged to upgrade to fixed versions as no additional mitigation is available.

CVE-2026-41726 was published on June 9, 2026, detailing a vulnerability in Spring for Apache Kafka. When applications use DelegatingDeserializer, producers can send records with unique random header values, leading to unbounded heap growth, GC thrashing, and potential OutOfMemoryError. Affected versions include Spring for Apache Kafka 4.0.0 to 4.0.5, 3.3.0 to 3.3.15, 3.2.0 to 3.2.13, 2.9.0 to 2.9.13, and 2.8.0 to 2.8.11. Users of these versions are advised to upgrade to fixed versions as no further mitigation steps are necessary. The vulnerability was discovered internally, and only deployments that explicitly configured DelegatingDeserializer are affected. This issue impacts users who have not yet upgraded to the corresponding fixed versions.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 92d ago How this analysis works

Timeline

2026-06-09
CVE-2026-41726 published
The vulnerability in Spring for Apache Kafka was officially disclosed, affecting multiple versions.
spring.io
2026-06-10
Security advisory released
Spring.io and The Hacker Wire reported on the vulnerability, urging users to upgrade affected versions.
Thehackerwire

More articles in this cluster (4)

Following this threat?

Track CVE-2026-41726 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed