Overview
About vulnerability
When an application opts intoDelegatingDeserializer, a producer can grow the consumer’s heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError.
Only deployments that explicitly configured DelegatingDeserializer are affected.
Details
- Affected product:
- Spring
- Affected packages:
- Spring Integration @ 5.5.19 (+390 more)