Vulnerability in Spring for Apache Kafka Headers by VMware
CVE-2026-59278

6.5MEDIUM

Key Information:

Vendor

Spring

Vendor
CVE Published:
27 August 2026

What is CVE-2026-59278?

A security vulnerability in Spring for Apache Kafka allows external Kafka producers to exploit the Java header mappers, specifically JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper. Due to the default configuration that trusts the java.net package, an attacker can inject instances of java.net.InetAddress through the spring_json_header_types message header. This behavior poses a risk as it could potentially lead to unauthorized actions within the application, thereby compromising system integrity.

Affected Version(s)

Spring for Apache Kafka 4.1.0

Spring for Apache Kafka 4.0.0 <= 4.0.6

Spring for Apache Kafka 3.0.0 <= 3.3.16

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.