kafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.py
Published Jun 10, 2026
8.7
HIGHCVSS 4.0
EPSS 0.52%
Description
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the client event loop by supplying an excessively large iteration count. In scram.py, ScramClient.process_server_first_message() passes the broker-controlled SCRAM iteration count directly to hashlib.pbkdf2_hmac() without validation, blocking producer sends, consumer polls, admin operations, and heartbeats, which can cause consumer group eviction and repeated reconnect failures.
Affected products
-
- Version 0StatusaffectedConstraints<2.3.2
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Dana Powers | Kafka-Python | n/a |
|
- < 2.3.2
No data.
Red Hat Quay 3.10
quay/quay-rhel8:1782487717
Fixed · RHSA-2026:33683
Red Hat Quay 3.12
quay/quay-rhel8:1781937357
Fixed · RHSA-2026:30076
Red Hat Quay 3.15
quay/quay-rhel8:1784351966
Fixed · RHSA-2026:42796
Red Hat Quay 3.16
quay/quay-rhel9:1783955846
Fixed · RHSA-2026:41066
Red Hat Quay 3.9
quay/quay-rhel8:1781878070
Fixed · RHSA-2026:28571
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Quay 3.10 | quay/quay-rhel8:1782487717 | Fixed | RHSA-2026:33683 |
| Red Hat Quay 3.12 | quay/quay-rhel8:1781937357 | Fixed | RHSA-2026:30076 |
| Red Hat Quay 3.15 | quay/quay-rhel8:1784351966 | Fixed | RHSA-2026:42796 |
| Red Hat Quay 3.16 | quay/quay-rhel9:1783955846 | Fixed | RHSA-2026:41066 |
| Red Hat Quay 3.9 | quay/quay-rhel8:1781878070 | Fixed | RHSA-2026:28571 |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (19)
- https://access.redhat.com/errata/RHSA-2026:28571
- https://access.redhat.com/errata/RHSA-2026:30076
- https://access.redhat.com/errata/RHSA-2026:33683
- https://access.redhat.com/errata/RHSA-2026:41066
- https://access.redhat.com/errata/RHSA-2026:42796
- https://access.redhat.com/security/cve/CVE-2026-10143 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2487722 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-36128 Advisory
- https://github.com/advisories/GHSA-2jcm-hq8r-84wx Advisory
- https://github.com/dpkp/kafka-python/commit/6e4831444f972d169cdd11f5c8d50333cea3f19b patch
- https://github.com/dpkp/kafka-python/commit/74400d7ef1b54ad24d4b8170c23b58d1cab65e4f
- https://github.com/dpkp/kafka-python/pull/3019 issue-trackingIssue TrackingPatch
- https://github.com/dpkp/kafka-python/pull/3026 issue-trackingIssue TrackingPatch
- https://github.com/dpkp/kafka-python/releases/tag/2.3.2
- https://github.com/pypa/advisory-database/tree/main/vulns/kafka-python/PYSEC-2026-2191.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2026-10143
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10143.json
- https://www.cve.org/CVERecord?id=CVE-2026-10143
- https://www.vulncheck.com/advisories/kafka-python-prior-to-dos-via-scram-iteration-count-in-scram-py third-party-advisoryPatchThird Party Advisory
Change history (0)
No recorded changes yet.