CVE-2026-59317
Last modified
CVE-2026-59317 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation. Spring for Apache Kafka 4.1.0 Spring for Apache Kafka 4.0.0 - 4.0.6 Spring for Apache Kafka 3.0.0 - 3.3.16 Spring for Apache Kafka 2.9.0 - 2.9.14 Spring for Apache Kafka 2.8.12 and earlier. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation. Spring for Apache Kafka 4.1.0 Spring for Apache Kafka 4.0.0 - 4.0.6 Spring for Apache Kafka 3.0.0 - 3.3.16 Spring for Apache Kafka 2.9.0 - 2.9.14 Spring for Apache Kafka 2.8.12 and earlier
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Spring For Apache Kafka | <= 2.8.12 |
| Vmware | Spring For Apache Kafka | >= 2.9.0, <= 2.9.14 |
| Vmware | Spring For Apache Kafka | >= 3.0.0, <= 3.3.16 |
| Vmware | Spring For Apache Kafka | >= 4.0.0, < 4.0.7 |
| Vmware | Spring For Apache Kafka | >= 4.1.0, < 4.1.1 |
References
- https://spring.io/security/cve-2026-59317Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-59317?
How severe is CVE-2026-59317?
How do I fix CVE-2026-59317?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-59310VMware vCenter contains a directory traversal vulnerability …9.8
- CVE-2026-59311A local unprivileged user on the same host can redirect all …6.8
- CVE-2026-59313Spring MVC applications using the functional web framework a…9.8
- CVE-2026-59314Applications that build a Content-Disposition header value f…3.7
- CVE-2026-59315The Spring Cloud Config Monitor is susceptible to Denial of …5.3
- CVE-2026-59316Spring Authorization Server's default consent page renders u…8.2
- CVE-2026-59318In Spring AI's tool calling support, the per-request tool li…9.8
- CVE-2026-59319RedisChatMemoryRepository.findByMetadata() builds RediSearch…4.3
- CVE-2026-59320When a container-level ErrorHandler is configured (the mitig…6.5
- CVE-2026-59321A single ScriptEngine instance is reused for every message o…5.4
- CVE-2026-59322The EmbeddedHeadersJsonMessageMapper defaults to an overly p…6.3
- CVE-2026-59323An application using Micrometer Tracing with W3C baggage pro…5.3
Are you affected by CVE-2026-59317?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
