CVE-2026-41726: Heap Growth Vulnerability in Spring for Apache Kafka

CVE-2026-41726: Heap Growth Vulnerability in Spring for Apache Kafka

First seen 10 Jun 2026, 09:30 UTC Thehackerwirespring.ionvd.nist.govwww.cvedetails.com 92% similarity 57.1

Article Content

Browse articles
ThreatCluster

CVE-2026-41726 was published on June 9, 2026, detailing a vulnerability in Spring for Apache Kafka. When applications use DelegatingDeserializer, producers can send records with unique random header values, leading to unbounded heap growth, GC thrashing, and potential OutOfMemoryError. Affected versions include Spring for Apache Kafka 4.0.0 to 4.0.5, 3.3.0 to 3.3.15, 3.2.0 to 3.2.13, 2.9.0 to 2.9.13, and 2.8.0 to 2.8.11. Users of these versions are advised to upgrade to fixed versions as no further mitigation steps are necessary. The vulnerability was discovered internally, and only deployments that explicitly configured DelegatingDeserializer are affected. This issue impacts users who have not yet upgraded to the corresponding fixed versions.

Key Points: • CVE-2026-41726 allows heap growth leading to OutOfMemoryError in specific Spring versions. • Affected versions include Spring for Apache Kafka 4.0.0 to 4.0.5 and earlier versions. • Users are urged to upgrade to fixed versions as no additional mitigation is available.

ThreatCluster AI

Timeline

2026-06-09
CVE-2026-41726 published
The vulnerability in Spring for Apache Kafka was officially disclosed, affecting multiple versions.
spring.io
2026-06-10
Security advisory released
Spring.io and The Hacker Wire reported on the vulnerability, urging users to upgrade affected versions.
Thehackerwire

Community

Browse all →

Tracked Entities in This Story