Deserialization Vulnerability in Spring for Apache Kafka by VMware
CVE-2026-41731
8.1HIGH
What is CVE-2026-41731?
A flaw in the JsonKafkaHeaderMapper and deprecated DefaultKafkaHeaderMapper allows type headers from trusted packages to be matched via a prefix check. This trust model could lead to arbitrary JDK types being deserialized when a producer supplies crafted header values, potentially compromising system integrity.
Affected Version(s)
Spring for Apache Kafka 4.0.0 < 4.0.5.1
Spring for Apache Kafka 3.3.0 < 3.3.15.1
Spring for Apache Kafka 3.2.0 < 3.2.14
