Back

HIGH

kafka-python prior to 2.3.2 Denial of Service via Protocol Parser Frame Length

Published Jun 10, 2026

Description

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length value without bounds validation. Attackers can send a specially crafted frame length through the receive_bytes() function to trigger either a multi-gigabyte memory allocation or an uncaught ValueError that leaves the connection in a broken state, causing requests to hang and consumers to stop heartbeating until restart.

Affected products

Remediation

Red Hat statement

A flaw was found in kafka-python. The protocol parser does not validate frame length values, allowing a malicious broker or man-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length. This can cause multi-gigabyte memory allocation or leave connections in a broken state, causing consumers to stop heartbeating until restart.

Red Hat mitigation

Upgrade to kafka-python 2.3.2 or later. As a workaround, ensure Kafka broker connections use TLS with mutual authentication to prevent man-in-the-middle attacks.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jun 10, 2026
Updated Jul 14, 2026
Reserved May 29, 2026
CISA Vulnrichment
Updated Jun 11, 2026
NVD
Status Analyzed
Modified Jul 23, 2026
Red Hat
Severity Moderate
Public date Jun 10, 2026
GHSA-M3PX-Q5GJ-J9X7