CVE-2026-41731

JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that caused the consumer to deserialize arbitrary JDK types. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:redhat:fuse:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*

History

23 Jul 2026, 09:10

Type Values Removed Values Added
Summary
  • (es) JsonKafkaHeaderMapper y el obsoleto DefaultKafkaHeaderMapper comparaban los encabezados de tipo con paquetes de confianza utilizando una comprobación de prefijo, lo que significaba que confiar en cualquier paquete confiaba implícitamente en todos sus subpaquetes. Combinado con la deserialización de beans predeterminada de Jackson, un productor podía suministrar valores de encabezado manipulados que hacían que el consumidor deserializara tipos JDK arbitrarios. Versiones afectadas: Spring para Apache Kafka 4.0.0 a 4.0.5; 3.3.0 a 3.3.15; 3.2.0 a 3.2.13; 2.9.0 a 2.9.13; 2.8.0 a 2.8.11.

17 Jul 2026, 20:31

Type Values Removed Values Added
References () https://access.redhat.com/security/cve/CVE-2026-41731 - () https://access.redhat.com/security/cve/CVE-2026-41731 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2487375 - () https://bugzilla.redhat.com/show_bug.cgi?id=2487375 - Issue Tracking, Third Party Advisory
References () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41731.json - () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41731.json - Third Party Advisory
CPE cpe:2.3:a:redhat:fuse:7.0.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:jboss_enterprise_application_platform_expansion_pack:-:*:*:*:*:*:*:*
First Time Redhat jboss Enterprise Application Platform Expansion Pack
Redhat fuse
Redhat

30 Jun 2026, 03:19

Type Values Removed Values Added
References
  • () https://access.redhat.com/security/cve/CVE-2026-41731 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2487375 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41731.json -

22 Jun 2026, 12:58

Type Values Removed Values Added
References () https://spring.io/security/cve-2026-41731 - () https://spring.io/security/cve-2026-41731 - Vendor Advisory
First Time Vmware
Vmware spring For Apache Kafka
CPE cpe:2.3:a:vmware:spring_for_apache_kafka:*:*:*:*:*:*:*:*

10 Jun 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-10 00:16

Updated : 2026-07-23 09:10


NVD link : CVE-2026-41731

Mitre link : CVE-2026-41731

CVE.ORG link : CVE-2026-41731


JSON object : View

Products Affected

redhat

  • jboss_enterprise_application_platform_expansion_pack
  • fuse

vmware

  • spring_for_apache_kafka
CWE
CWE-502

Deserialization of Untrusted Data