Spring Kafka Support
92%
Total Score
99
51
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-11171 spring-kafka is vulnerable to Deserialization of Untrusted Data in versions 0.0.1 - 2.8.11, 2.9.0 - 2.9.13, 3.0.0 - 3.2.13, 3.3.0 - 3.3.15 and 4.0.0 - 4.0.5. | 0.0.1 - 2.8.112.9.0 - 2.9.133.0.0 - 3.2.13 +2 more | High |
AIKIDO-2026-11174 spring-kafka is vulnerable to Improper Input Validation in versions 0.0.1 - 2.8.11, 2.9.0 - 2.9.13, 3.0.0 - 3.2.13, 3.3.0 - 3.3.15 and 4.0.0 - 4.0.5. | 0.0.1 - 2.8.112.9.0 - 2.9.133.0.0 - 3.2.13 +2 more | Medium |
AIKIDO-2026-11176 spring-kafka is vulnerable to Allocation of Resources Without Limits or Throttling in versions 0.0.1 - 2.8.11, 2.9.0 - 2.9.13, 3.0.0 - 3.2.13, 3.3.0 - 3.3.15 and 4.0.0 - 4.0.5. | 0.0.1 - 2.8.112.9.0 - 2.9.133.0.0 - 3.2.13 +2 more | Medium |
CVE-2023-34040 org.springframework.kafka:spring-kafka is vulnerable to Deserialization of Untrusted Data in versions 3.0.0 - 3.0.10 and 2.8.1 - 2.9.11. | 2.8.1 - 2.9.113.0.0 - 3.0.10 | High |
No maintainer information available.
| Dependency | Last Release | Score |
|---|---|---|
org.springframework:spring-context Version 7.0.8 | — | — |
org.springframework:spring-messaging Version 7.0.8 | — | — |
org.springframework:spring-tx Version 7.0.8 | — | — |
org.apache.kafka:kafka-clients Version 4.2.1 | — | — |
io.micrometer:micrometer-observation Version 1.17.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant