DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation.
Spring for Apache Kafka 4.1.0
Spring for Apache Kafka 4.0.0 - 4.0.6
Spring for Apache Kafka 3.0.0 - 3.3.16
Spring for Apache Kafka 2.9.0 - 2.9.14
Spring for Apache Kafka 2.8.12 and earlier
References
| Link | Resource |
|---|---|
| https://spring.io/security/cve-2026-59317 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2026-08-27 20:17
Updated : 2026-09-04 19:21
NVD link : CVE-2026-59317
Mitre link : CVE-2026-59317
CVE.ORG link : CVE-2026-59317
JSON object : View
Products Affected
vmware
- spring_for_apache_kafka
CWE
CWE-1284
Improper Validation of Specified Quantity in Input
