Spring for Apache Kafka

2 known vulnerabilities in Spring for Apache Kafka, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-59317 CVSS 6.5 medium DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw…
  • CVE-2026-59278 CVSS 6.5 medium JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used …