« Volver al listado

CVE-2026-41726

Estado: AnalizadaMedia (6.5)—

When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.

Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-41726",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-41726",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-10T17:38:31.984058Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Spring",
          "product": "Spring for Apache Kafka",
          "versions": [
            {
              "status": "affected",
              "version": "4.0.0",
              "lessThan": "4.0.5.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.3.0",
              "lessThan": "3.3.15.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "3.2.0",
              "lessThan": "3.2.14",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.9.0",
              "lessThan": "2.9.14",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "2.8.0",
              "lessThan": "2.8.12",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-10T00:16:52.030",
  "references": [
    {
      "url": "https://spring.io/security/cve-2026-41726",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@vmware.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.\n\nAffected versions:\nSpring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11."
    },
    {
      "lang": "es",
      "value": "Cuando una aplicación opta por DelegatingDeserializer, un productor puede aumentar el heap del consumidor sin límite enviando registros con valores de encabezado spring.kafka.serialization.selector únicos aleatorios, lo que finalmente causa agotamiento del GC y OutOfMemoryError.\n\nVersiones afectadas:\nSpring for Apache Kafka 4.0.0 hasta 4.0.5; 3.3.0 hasta 3.3.15; 3.2.0 hasta 3.2.13; 2.9.0 hasta 2.9.13; 2.8.0 hasta 2.8.11."
    }
  ],
  "lastModified": "2026-07-23T09:10:00.113",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1B04126-FFDD-4EC7-B4B9-3050489B3682",
              "versionEndExcluding": "2.8.12"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA023945-8D2F-4B64-8819-AA41F087BC18",
              "versionEndExcluding": "2.9.14",
              "versionStartIncluding": "2.9.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "63E0CB29-F9CC-498A-8795-1344AECBBA74",
              "versionEndExcluding": "3.2.14",
              "versionStartIncluding": "3.2.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2A5CE749-924C-46F0-AD18-1FAE9FA29FCC",
              "versionEndExcluding": "3.3.15.1",
              "versionStartIncluding": "3.3.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "00C97EF8-CDE8-47B9-B1B6-9DE53F3FF907",
              "versionEndExcluding": "4.0.5.1",
              "versionStartIncluding": "4.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}