Input validation error in Spring for Apache Kafka - CVE-2026-41727
Published: August 31, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper input validation in the retry topic infrastructure when processing user-controlled retry headers. A remote user can send a record with crafted retry headers to cause a denial of service.
The issue affects handling of the retry_topic-attempts and retry_topic_backoff-timestamp headers.