When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.8.12CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:* | ||
>= 2.9.0, < 2.9.14CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:* | ||
>= 3.2.0, < 3.2.14CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:* | ||
>= 3.3.0, < 3.3.15.1CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.5.1CPE matchmatch criteria | cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.