A AegiFlow
MEDIUMCVSS 6.5EPSS 0.2%

CVE-2026-41727

CVE-2026-41727 updated by NVD

Published
2026-06-10
Modified
2026-08-12
EPSS percentile
15%
Sources
github-advisory, nvd

Summary

Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause the retry topic router to misidentify where the message was in the retry sequence. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.springframework.kafka:spring-kafka4.0.6, 3.3.16

Remediation: Upgrade to 4.0.6 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.