Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-41726

27
FAUCET Score

When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.

First published: Jun 9, 2026Last modified: Jun 27, 2026

Impacted Technologies

VendorProductVersion(s)CPE
< 2.8.12CPE matchmatch criteria
cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*
>= 2.9.0, < 2.9.14CPE matchmatch criteria
cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*
>= 3.2.0, < 3.2.14CPE matchmatch criteria
cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*
>= 3.3.0, < 3.3.15.1CPE matchmatch criteria
cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*
>= 4.0.0, < 4.0.5.1CPE matchmatch criteria
cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.30%
Probability of exploitation in next 30 days
EPSS Percentile
21.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0030 is in the 28th percentile among its peer group of 21,957 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

mavenpatch availablevia ghsa
Product: org.springframework.kafka:spring-kafkaFixed in: 4.0.6
mavenpatch availablevia ghsa
Product: org.springframework.kafka:spring-kafkaFixed in: 3.3.16

Vendor Advisories (1)

mavenGHSA-xvfq-4q6q-gxx7medium

In Spring for Apache Kafka, unbounded delegate cache keyed on user-controlled, potentially malicious selector header

Jun 10, 2026

References

spring.io / security/cve-2026-41726
Vendor Advisory