Heap Memory Vulnerability in Spring for Apache Kafka
CVE-2026-41726

6.5MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
9 June 2026

What is CVE-2026-41726?

This vulnerability occurs when an application utilizing the DelegatingDeserializer feature can be exploited by a producer to excessively increase the heap memory of a consumer. By sending records with unique random selector header values, the producer can lead the consumer into a state of uncontrollable heap growth, resulting in frequent garbage collection and potentially causing an OutOfMemoryError. This behavior exposes the application to performance degradation and stability issues, making it essential for organizations to address this vulnerability to maintain optimal operations.

Affected Version(s)

Spring for Apache Kafka 4.0.0 < 4.0.5.1

Spring for Apache Kafka 3.3.0 < 3.3.15.1

Spring for Apache Kafka 3.2.0 < 3.2.14

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.