spring-kafka is vulnerable to Allocation of Resources Without Limits or Throttling
55
Medium Risk
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.
You are affected if you are using a version that falls within the vulnerable range and if you explicitly configured DelegatingDeserializer.
spring-kafka is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.0.1 - 2.8.11, 2.9.0 - 2.9.13, 3.0.0 - 3.2.13, 3.3.0 - 3.3.15 and 4.0.0 - 4.0.5.
Upgrade the org.springframework.kafka:spring-kafka library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant