Input validation error in Spring for Apache Kafka - CVE-2026-59317
Published: August 28, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in DeadLetterPublishingRecovererFactory when processing the retry_topic-original-timestamp header from an inbound ConsumerRecord during recovery. A remote user can send a malformed header value to cause a denial of service.
Exploitation can cause dead-letter publication to abort, after which the error handler seeks back to the failed offset and repeats the cycle indefinitely, stalling partition consumption.
Affected software
Library Support for Spring
How to mitigate CVE-2026-59317
Library Support for Spring - update to 3.5.19