Bug 2524842 (CVE-2026-59278)

Summary: CVE-2026-59278 org.springframework.kafka/spring-kafka: Spring for Apache Kafka: Server-Side Request Forgery via untrusted Java types in header mappers
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: gmalinko, gtanzill, janstey, jbuscemi, pdelbell, rstepani
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Spring for Apache Kafka. The JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper components, which are used by default in @KafkaListener consumers, include java.net in their list of trusted packages. This allows a remote attacker, by sending a specially crafted message, to inject a java.net.InetAddress type through the spring_json_header_types message header. This can lead to Server-Side Request Forgery (SSRF) via DNS resolution, potentially enabling information disclosure or other network-based attacks.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-08-27 06:22:10 UTC
JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer can inject a java.net.InetAddress type via the spring_json_header_types message header.
Spring for Apache Kafka 4.1.0
Spring for Apache Kafka 4.0.0 - 4.0.6
Spring for Apache Kafka 3.0.0 - 3.3.16
Spring for Apache Kafka 2.9.0 - 2.9.14
Spring for Apache Kafka 2.8.12 and earlier