Vulnerability in Spring for Apache Kafka Headers by VMware
CVE-2026-59278
6.5MEDIUM
What is CVE-2026-59278?
A security vulnerability in Spring for Apache Kafka allows external Kafka producers to exploit the Java header mappers, specifically JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper. Due to the default configuration that trusts the java.net package, an attacker can inject instances of java.net.InetAddress through the spring_json_header_types message header. This behavior poses a risk as it could potentially lead to unauthorized actions within the application, thereby compromising system integrity.
Affected Version(s)
Spring for Apache Kafka 4.1.0
Spring for Apache Kafka 4.0.0 <= 4.0.6
Spring for Apache Kafka 3.0.0 <= 3.3.16
