Bug 2525176 (CVE-2026-59317) - CVE-2026-59317 org.springframework.kafka/spring-kafka: Spring for Apache Kafka: Denial of Service via missing header validation
Summary: CVE-2026-59317 org.springframework.kafka/spring-kafka: Spring for Apache Kafk...
Keywords:
Status: NEW
Alias: CVE-2026-59317
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-27 20:13 UTC by OSIDB Bzimport
Modified: 2026-09-18 07:36 UTC (History)
6 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-27 20:13:14 UTC
DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation.
Spring for Apache Kafka 4.1.0
Spring for Apache Kafka 4.0.0 - 4.0.6
Spring for Apache Kafka 3.0.0 - 3.3.16
Spring for Apache Kafka 2.9.0 - 2.9.14
Spring for Apache Kafka 2.8.12 and earlier


Note You need to log in before you can comment on or make changes to this bug.