Skip to main content

Vendor/product archive

apache / kafka CVEs

Beta · best-effort

16 CVEs tagged to apache / kafka1 Critical, 7 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2026-41115

Published Jun 2, 2026

An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GR…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-33558

Published Apr 20, 2026

Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level i…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2026-33557

Published Apr 20, 2026

A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.s…

CVSS 9.1 · Critical
evidence mentions
6
Buzz score
35.5
Vendor/product tagsBeta · best-effort

CVE-2025-27819

Published Jun 10, 2025

In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27818

Published Jun 10, 2025

A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-27817

Published Jun 10, 2025

A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-56128

Published Dec 18, 2024

Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Salted Challenge Response Authent…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-31141

Published Nov 19, 2024

Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for custo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-27309

Published Apr 12, 2024

While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions are needed to trigger the…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2022-34917

Published Sep 20, 2022

A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated clients to allocate large amo…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-38153

Published Sep 22, 2021

Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more li…

CVSS 5.9 · Medium

CVE-2018-17196

Published Jul 11, 2019

In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated cl…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-12610

Published Jul 26, 2018

In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SC…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-16 of 16 CVEsPage 1 of 1