JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer can inject a java.net.InetAddress type via the spring_json_header_types message header.
Spring for Apache Kafka 4.1.0
Spring for Apache Kafka 4.0.0 - 4.0.6
Spring for Apache Kafka 3.0.0 - 3.3.16
Spring for Apache Kafka 2.9.0 - 2.9.14
Spring for Apache Kafka 2.8.12 and earlier
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-59278 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-27 06:17
Updated : 2026-09-01 16:07
NVD link : CVE-2026-59278
Mitre link : CVE-2026-59278
CVE.ORG link : CVE-2026-59278
JSON object : View
Products Affected
vmware
- spring_for_apache_kafka
CWE
CWE-918
Server-Side Request Forgery (SSRF)
