Trust Issues in Spring for Apache Pulsar from Pivotal
CVE-2026-41732
8.1HIGH
What is CVE-2026-41732?
A vulnerability in Spring for Apache Pulsar allows for the potential exploitation of trusted package configurations. JsonPulsarHeaderMapper lacks proper verification of type headers, enabling attackers to leverage implicit trust in subpackages. In instances of an empty trusted-packages configuration, the default behavior escalates the risk by trusting all packages without a secure allow-list, thereby exposing systems to possible unauthorized access and malicious code execution.
Affected Version(s)
Spring for Apache Pulsar 2.0.0 < 2.0.5.1
Spring for Apache Pulsar 1.2.0 < 1.2.17.1
Spring for Apache Pulsar 1.1.0 < 1.1.18
