CVE-2023-34040 is a Java deserialization vulnerability in Spring for Apache Kafka affecting versions 3.0.9 and earlier and 2.9.10 and earlier. The issue arises from unsafe handling of deserialization exception record headers under a specific non-default configuration. An attacker can place a malicious serialized object into a deserialization exception header and have it processed by the application when the listener container is configured to inspect deserialization exceptions even when the key or value is null. The vulnerable condition exists only when an ErrorHandlingDeserializer is not configured for the key and/or value, the container properties checkDeserExWhenKeyNull and/or checkDeserExWhenValueNull are explicitly enabled, and untrusted producers are allowed to publish records to the relevant Kafka topic. By default, the affected properties are disabled, and use of ErrorHandlingDeserializer prevents exploitation by stripping malicious headers before record processing.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a proof-of-concept (POC) exploit for a deserialization vulnerability in Spring-Kafka consumer applications. It consists of two main Java applications: a producer and a consumer, each with their own Maven project structure. The exploit demonstrates how an attacker can craft a serialized Java object (specifically, a DeserializationException object) and inject it into Kafka message headers. The consumer, when configured with 'CheckDeserExWhenValueNull' and/or 'CheckDeserExWhenKeyNull', will attempt to deserialize this object. The exploit provides two payloads: a denial-of-service (DoS) payload using a 'billion laughs' style nested Set object, and a remote code execution (RCE) payload using a custom ProcBuilder gadget that executes arbitrary commands (e.g., 'touch /tmp/newfile'). The exploit leverages the fact that Spring-Kafka only checks the top-level class name during deserialization, which can be bypassed by modifying the serialized data. The repository includes Docker Compose files for setting up Kafka and Zookeeper, and all necessary configuration files for running the POC. The main attack vector is network-based, targeting Kafka consumers via crafted messages sent to Kafka topics. The exploit is not weaponized but serves as a clear demonstration of the vulnerability and its impact.
This repository is a proof-of-concept exploit for CVE-2023-34040, a deserialization remote code execution vulnerability in Spring for Apache Kafka. The project is a Spring Boot application that exposes an HTTP endpoint at /messages/send (on 127.0.0.1:8899). When a POST request is made to this endpoint with a specially crafted JSON payload, the application constructs a Kafka message with headers that include a serialized Java exception object. The consumer is configured to trust all packages for deserialization, making it vulnerable to arbitrary code execution. The included MaliciousClass demonstrates a payload that executes a system command (launches calculator) upon deserialization. The repository includes all necessary configuration and code to demonstrate the exploit, including Kafka producer/consumer setup, the malicious payload, and example usage in the README. The main attack vector is network-based, requiring access to the HTTP endpoint and the Kafka infrastructure.
This repository is a proof-of-concept exploit for CVE-2023-34040, a remote code execution vulnerability in Spring for Apache Kafka due to unsafe deserialization. The project is a Spring Boot application that exposes an HTTP endpoint (/messages/send) which accepts JSON data, constructs a Kafka message, and sends it to a Kafka broker. The exploit leverages a maliciously crafted serialized Java object (using Commons Collections gadget chains) to trigger code execution on the consumer side when deserialization occurs. The payload demonstrates execution of the 'open -a calculator' command. The repository includes code to generate the malicious serialized object, configuration for the Kafka producer and consumer, and a sample application.yaml specifying the HTTP server and Kafka broker endpoints. The main attack vector is network-based, targeting the HTTP endpoint and Kafka infrastructure. The exploit is a working POC and not weaponized, as it requires manual payload crafting and setup.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.