CVE-2026-41731: In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization
Spring
·
2026-06-09
·
via Spring Security Advisories
Description JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against tr…
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。