spring.io
CVE-2026-41726: Heap Growth Vulnerability in Spring for Apache Kafka
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
CVE-2026-41726 was published on June 9, 2026, detailing a vulnerability in Spring for Apache Kafka. When applications use DelegatingDeserializer, producers can send records with unique random header values, leading to unbounded heap growth, GC thrashing, and potential OutOfMemoryError. Affected versions include Spring for Apache Kafka 4.0.0 to 4.0.5, 3.3.0 to 3.3.15, 3.2.0 to 3.2.13, 2.9.0 to 2.9.13, and 2.8.0 to 2.8.11. Users of these versions are advised to upgrade to fixed versions as no further mitigation steps are necessary. The vulnerability was discovered internally, and only deployments that explicitly configured DelegatingDeserializer are affected. This issue impacts users who have not yet upgraded to the corresponding fixed versions.
Key Points: • CVE-2026-41726 allows heap growth leading to OutOfMemoryError in specific Spring versions. • Affected versions include Spring for Apache Kafka 4.0.0 to 4.0.5 and earlier versions. • Users are urged to upgrade to fixed versions as no additional mitigation is available.