CVE-2026-33557
- EPSS 0.2%
- Veröffentlicht 20.04.2026 13:28:43
- Zuletzt bearbeitet 22.04.2026 14:14:52
A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token with...
CVE-2026-33558
- EPSS 0.14%
- Veröffentlicht 20.04.2026 13:20:38
- Zuletzt bearbeitet 22.04.2026 14:16:12
Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBU...
CVE-2026-35554
- EPSS 0.04%
- Veröffentlicht 07.04.2026 13:07:08
- Zuletzt bearbeitet 08.04.2026 21:27:15
A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containing that batch...
CVE-2025-27817
- EPSS 21.42%
- Veröffentlicht 10.06.2025 07:55:14
- Zuletzt bearbeitet 11.07.2025 16:58:15
A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including "sasl.oauthbearer.token.endpoint....
CVE-2025-27819
- EPSS 0.9%
- Veröffentlicht 10.06.2025 07:54:41
- Zuletzt bearbeitet 11.07.2025 16:52:33
In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To ...
CVE-2025-27818
- EPSS 0.68%
- Veröffentlicht 10.06.2025 07:52:31
- Zuletzt bearbeitet 11.07.2025 16:54:35
A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS ...
CVE-2024-56128
- EPSS 0.53%
- Veröffentlicht 18.12.2024 14:15:23
- Zuletzt bearbeitet 20.06.2025 18:13:13
Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Salted Challenge Response Authentication Mechanism (SCRAM) did not fully adhere to the requirements of R...
CVE-2024-31141
- EPSS 0.16%
- Veröffentlicht 19.11.2024 09:15:03
- Zuletzt bearbeitet 15.07.2025 16:42:34
Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipu...
CVE-2024-27309
- EPSS 0.39%
- Veröffentlicht 12.04.2024 07:15:08
- Zuletzt bearbeitet 10.06.2025 00:59:50
While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions are needed to trigger the bug: 1. The administrator decides to remove an ACL 2. The resource asso...
CVE-2022-34917
- EPSS 0.07%
- Veröffentlicht 20.09.2022 09:15:09
- Zuletzt bearbeitet 29.05.2025 14:15:28
A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated clients to allocate large amounts of memory on brokers. This can lead to brokers hitting OutOfMemory...