« Volver al listado

CVE-2026-41732

Estado: AnalizadaAlta (8.1)—

JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trusting all packages rather than applying a safe default allow-list.

Affected versions: Spring for Apache Pulsar 2.0.0 through 2.0.5; 1.2.0 through 1.2.17; 1.1.0 through 1.1.17.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

CWE-502 (deserialización insegura) con acceso remoto sin autenticación (AV:N/PR:N) permite ejecución remota de código. La configuración débil de paquetes de confianza en JsonPulsarHeaderMapper posibilita inyección de gadgets maliciosos.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-41732",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-41732",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-06-10T18:52:35.652237Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@vmware.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 8.1,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.2
      }
    ]
  },
  "affected": [
    {
      "source": "security@vmware.com",
      "affectedData": [
        {
          "vendor": "Spring",
          "product": "Spring for Apache Pulsar",
          "versions": [
            {
              "status": "affected",
              "version": "2.0.0",
              "lessThan": "2.0.5.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.2.0",
              "lessThan": "1.2.17.1",
              "versionType": "custom"
            },
            {
              "status": "affected",
              "version": "1.1.0",
              "lessThan": "1.1.18",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-06-10T00:16:52.720",
  "references": [
    {
      "url": "https://spring.io/security/cve-2026-41732",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@vmware.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@vmware.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-502"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trusting all packages rather than applying a safe default allow-list.\n\nAffected versions:\nSpring for Apache Pulsar 2.0.0 through 2.0.5; 1.2.0 through 1.2.17; 1.1.0 through 1.1.17."
    },
    {
      "lang": "es",
      "value": "JsonPulsarHeaderMapper comparaba los encabezados de tipo con paquetes de confianza utilizando una comprobación de prefijo, lo que significa que confiar en cualquier paquete implicaba confiar implícitamente en todos sus subpaquetes. Además, una configuración vacía de trusted-packages recurría a confiar en todos los paquetes en lugar de aplicar una lista de permitidos predeterminada segura.\n\nVersiones afectadas:\nSpring for Apache Pulsar 2.0.0 a 2.0.5; 1.2.0 a 1.2.17; 1.1.0 a 1.1.17."
    }
  ],
  "lastModified": "2026-07-23T09:10:00.113",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_apache_pulsar:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BD99C33F-8DEF-4A9D-B331-C1FED95A6726",
              "versionEndExcluding": "1.1.18",
              "versionStartIncluding": "1.1.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_apache_pulsar:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CBA155E6-BFC7-4EAA-915C-9A542A9151B9",
              "versionEndExcluding": "1.2.17.1",
              "versionStartIncluding": "1.2.0"
            },
            {
              "criteria": "cpe:2.3:a:vmware:spring_for_apache_pulsar:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "301B7FE5-CDDF-4CE4-BC3F-0AE886D6FF26",
              "versionEndExcluding": "2.0.6",
              "versionStartIncluding": "2.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@vmware.com"
}