Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
Published Apr 7, 2026
8.7
HIGHCVSS 3.1
EPSS 0.65%
Description
A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics.
When a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still in flight, the batch’s ByteBuffer is prematurely deallocated and returned to the buffer pool. If a subsequent producer batch—potentially destined for a different topic—reuses this freed buffer before the original network request completes, the buffer contents may become corrupted. This can result in messages being delivered to unintended topics without any error being reported to the producer.
Data Confidentiality: Messages intended for one topic may be delivered to a different topic, potentially exposing sensitive data to consumers who have access to the destination topic but not the intended source topic.
Data Integrity: Consumers on the receiving topic may encounter unexpected or incompatible messages, leading to deserialization failures, processing errors, and corrupted downstream data.
This issue affects Apache Kafka versions ≤ 3.9.1, ≤ 4.0.1, and ≤ 4.1.1.
Kafka users are advised to upgrade to 3.9.2, 4.0.2, 4.1.2, 4.2.0, or later to address this vulnerability.
Affected products
-
- Version 2.8.0StatusaffectedConstraints<=3.9.1
- Version 4.0.0StatusaffectedConstraints<=4.0.1
- Version 4.1.0StatusaffectedConstraints<=4.1.1
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Kafka Clients | unaffected |
|
No data.
Red Hat Build of Apache Camel 4.14 for Quarkus 3.27
kafka-clients
Fixed · RHSA-2026:13631
Red Hat JBoss Enterprise Application Platform 6.0.5.GA
org.apache.kafka/kafka-clients:3.9.2.redhat-00001
Fixed · RHSA-2026:42098
Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14
kafka-clients
Fixed · RHSA-2026:17668
Red Hat build of Quarkus 3.27.3.SP1
kafka-clients
Fixed · RHSA-2026:11721
Streams for Apache Kafka 3.2.1
kafka-clients
Fixed · RHSA-2026:54435
OpenShift Serverless
openshift-serverless-1/kn-ekb-dispatcher-rhel9
Affected
OpenShift Serverless
openshift-serverless-1/kn-ekb-receiver-rhel9
Affected
Red Hat Data Grid 8
kafka-clients
Not affected
Red Hat Enterprise Linux 8
log4j:2/log4j
Not affected
Red Hat Enterprise Linux 9
log4j
Not affected
Red Hat Fuse 7
kafka-clients
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
kafka-clients
Out of support scope
Red Hat JBoss Enterprise Application Platform 8
kafka-clients
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
kafka-clients
Affected
Red Hat Process Automation 7
kafka-clients
Out of support scope
Red Hat build of Apache Camel 4 for Quarkus 3
kafka-clients
Affected
Red Hat build of Apicurio Registry 2
kafka-clients
Will not fix
Red Hat build of Apicurio Registry 3
kafka-clients
Affected
Red Hat build of Debezium 2
kafka-clients
Out of support scope
Red Hat build of Debezium 3
kafka-clients
Will not fix
streams for Apache Kafka 2
kafka-clients
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Build of Apache Camel 4.14 for Quarkus 3.27 | kafka-clients | Fixed | RHSA-2026:13631 |
| Red Hat JBoss Enterprise Application Platform 6.0.5.GA | org.apache.kafka/kafka-clients:3.9.2.redhat-00001 | Fixed | RHSA-2026:42098 |
| Red Hat build of Apache Camel 4.18.1 for Spring Boot 3.5.14 | kafka-clients | Fixed | RHSA-2026:17668 |
| Red Hat build of Quarkus 3.27.3.SP1 | kafka-clients | Fixed | RHSA-2026:11721 |
| Streams for Apache Kafka 3.2.1 | kafka-clients | Fixed | RHSA-2026:54435 |
| OpenShift Serverless | openshift-serverless-1/kn-ekb-dispatcher-rhel9 | Affected | n/a |
| OpenShift Serverless | openshift-serverless-1/kn-ekb-receiver-rhel9 | Affected | n/a |
| Red Hat Data Grid 8 | kafka-clients | Not affected | n/a |
| Red Hat Enterprise Linux 8 | log4j:2/log4j | Not affected | n/a |
| Red Hat Enterprise Linux 9 | log4j | Not affected | n/a |
| Red Hat Fuse 7 | kafka-clients | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | kafka-clients | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | kafka-clients | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | kafka-clients | Affected | n/a |
| Red Hat Process Automation 7 | kafka-clients | Out of support scope | n/a |
| Red Hat build of Apache Camel 4 for Quarkus 3 | kafka-clients | Affected | n/a |
| Red Hat build of Apicurio Registry 2 | kafka-clients | Will not fix | n/a |
| Red Hat build of Apicurio Registry 3 | kafka-clients | Affected | n/a |
| Red Hat build of Debezium 2 | kafka-clients | Out of support scope | n/a |
| Red Hat build of Debezium 3 | kafka-clients | Will not fix | n/a |
| streams for Apache Kafka 2 | kafka-clients | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Apr 7, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
Apr–Oct 2026- EPSS v4
- EPSS v5
Percentile over time
- EPSS v4
- EPSS v5
Table of values (3 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 0.65% (0.00647) | 49.21th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.33% (0.00328) | 24.34th | v5 (v2026.06.15) |
| Apr 8, 2026 | 0.03% (0.00028) | 7.91th | v4 (v2025.03.14) |
References (14)
- http://www.openwall.com/lists/oss-security/2026/04/07/6 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2026-35554 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2455916 Issue Tracking
- https://github.com/advisories/GHSA-5qcv-4rpc-jp93 Advisory
- https://github.com/apache/kafka/commit/1df2ac5b2ba4d1b5ed54b895ff6fb9539303ccb5
- https://github.com/apache/kafka/pull/21065
- https://github.com/apache/kafka/pull/21285
- https://github.com/apache/kafka/pull/21286
- https://github.com/apache/kafka/pull/21287
- https://github.com/apache/kafka/pull/21288
- https://issues.apache.org/jira/browse/KAFKA-19012 issue-trackingIssue Tracking
- https://lists.apache.org/thread/f07x7j8ovyqhjd1to25jsnqbm6wj01d6 mailing-listvendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-35554
- https://www.cve.org/CVERecord?id=CVE-2026-35554
Change history (0)
No recorded changes yet.