CVE-2026-41726
Estado: AnalizadaMedia (6.5)—
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.
Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 6.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.42%
- Percentil entre todas las CVEs puntuadas: 34
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-770
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-41726",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-41726",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-06-10T17:38:31.984058Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security@vmware.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.5,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 2.8
}
]
},
"affected": [
{
"source": "security@vmware.com",
"affectedData": [
{
"vendor": "Spring",
"product": "Spring for Apache Kafka",
"versions": [
{
"status": "affected",
"version": "4.0.0",
"lessThan": "4.0.5.1",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.3.0",
"lessThan": "3.3.15.1",
"versionType": "custom"
},
{
"status": "affected",
"version": "3.2.0",
"lessThan": "3.2.14",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.9.0",
"lessThan": "2.9.14",
"versionType": "custom"
},
{
"status": "affected",
"version": "2.8.0",
"lessThan": "2.8.12",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-06-10T00:16:52.030",
"references": [
{
"url": "https://spring.io/security/cve-2026-41726",
"tags": [
"Vendor Advisory"
],
"source": "security@vmware.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "security@vmware.com",
"description": [
{
"lang": "en",
"value": "CWE-770"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.\n\nAffected versions:\nSpring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11."
},
{
"lang": "es",
"value": "Cuando una aplicación opta por DelegatingDeserializer, un productor puede aumentar el heap del consumidor sin límite enviando registros con valores de encabezado spring.kafka.serialization.selector únicos aleatorios, lo que finalmente causa agotamiento del GC y OutOfMemoryError.\n\nVersiones afectadas:\nSpring for Apache Kafka 4.0.0 hasta 4.0.5; 3.3.0 hasta 3.3.15; 3.2.0 hasta 3.2.13; 2.9.0 hasta 2.9.13; 2.8.0 hasta 2.8.11."
}
],
"lastModified": "2026-07-23T09:10:00.113",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A1B04126-FFDD-4EC7-B4B9-3050489B3682",
"versionEndExcluding": "2.8.12"
},
{
"criteria": "cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AA023945-8D2F-4B64-8819-AA41F087BC18",
"versionEndExcluding": "2.9.14",
"versionStartIncluding": "2.9.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "63E0CB29-F9CC-498A-8795-1344AECBBA74",
"versionEndExcluding": "3.2.14",
"versionStartIncluding": "3.2.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2A5CE749-924C-46F0-AD18-1FAE9FA29FCC",
"versionEndExcluding": "3.3.15.1",
"versionStartIncluding": "3.3.0"
},
{
"criteria": "cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "00C97EF8-CDE8-47B9-B1B6-9DE53F3FF907",
"versionEndExcluding": "4.0.5.1",
"versionStartIncluding": "4.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security@vmware.com"
}