A AegiFlow
HIGHCVSS 8.1EPSS 0.3%

CVE-2026-41732

CVE-2026-41732 updated by NVD

Published
2026-06-10
Modified
2026-08-12
EPSS percentile
28%
Sources
github-advisory, nvd

Summary

JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trusting all packages rather than applying a safe default allow-list. Affected versions: Spring for Apache Pulsar 2.0.0 through 2.0.5; 1.2.0 through 1.2.17; 1.1.0 through 1.1.17.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.springframework.pulsar:spring-pulsar2.0.6, 1.2.18

Remediation: Upgrade to 2.0.6 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.