Home

Description

When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.

PUBLISHED Reserved 2026-04-22 | Published 2026-06-09 | Updated 2026-06-10 | Assigner vmware




MEDIUM: 6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-770: Allocation of Resources Without Limits or Throttling

Product status

Default status
unaffected

4.0.0 (custom) before 4.0.6
affected

3.3.0 (custom) before 3.3.16
affected

3.2.0 (custom) before 3.2.14
affected

2.9.0 (custom) before 2.9.14
affected

2.8.0 (custom) before 2.8.12
affected

References

spring.io/security/cve-2026-41726

cve.org (CVE-2026-41726)

nvd.nist.gov (CVE-2026-41726)

Download JSON