Vulnerability Description
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that caused the consumer to deserialize arbitrary JDK types. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0 through 3.3.15; 3.2.0 through 3.2.13; 2.9.0 through 2.9.13; 2.8.0 through 2.8.11.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Spring For Apache Kafka | >= 2.8.0, < 2.8.12 |
| Redhat | Fuse | 7.0.0 |
| Redhat | Jboss Enterprise Application Platform Expansion Pack | - |
Related Weaknesses (CWE)
References
- https://spring.io/security/cve-2026-41731Vendor Advisory
- https://access.redhat.com/security/cve/CVE-2026-41731Third Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2487375Issue TrackingThird Party Advisory
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-41731.jsonThird Party Advisory
FAQ
What is CVE-2026-41731?
CVE-2026-41731 is a vulnerability with a CVSS score of 8.1 (HIGH). JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its su...
How severe is CVE-2026-41731?
CVE-2026-41731 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-41731?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Spring For Apache Kafka, Redhat Fuse, Redhat Jboss Enterprise Application Platform Expansion Pack.