Apache / Kafka
17 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-41115 | Apache Kafka: Improper Authorization in CONSUMER_GROUP_DESCRIBE API | MEDIUM | 6.5 | Jun 2, 2026 |
| CVE-2026-33557 | Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication | CRITICAL | 9.1 | Apr 20, 2026 |
| CVE-2026-33558 | Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output | MEDIUM | 5.3 | Apr 20, 2026 |
| CVE-2026-35554 | Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition | HIGH | 8.7 | Apr 7, 2026 |
| CVE-2025-27817 | Apache Kafka Client: Arbitrary file read and SSRF vulnerability | MEDIUM | 6.2 | Jun 10, 2025 |
| CVE-2025-27819 | Apache Kafka: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration | HIGH | 8.8 | Jun 10, 2025 |
| CVE-2025-27818 | Apache Kafka: Possible RCE attack via SASL JAAS LdapLoginModule configuration | HIGH | 8.8 | Jun 10, 2025 |
| CVE-2024-56128 | Apache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryption | LOW | 1.7 | Dec 18, 2024 |
| CVE-2024-31141 | Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider | MEDIUM | 6.8 | Nov 19, 2024 |
| CVE-2024-27309 | Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode | HIGH | 7.6 | Apr 12, 2024 |
| CVE-2022-34917 | Unauthenticated clients may cause OutOfMemoryError on Apache Kafka Brokers | HIGH | 7.5 | Sep 20, 2022 |
| CVE-2021-38153 | Timing Attack Vulnerability for Apache Kafka Connect and Clients | MEDIUM | 5.9 | Sep 22, 2021 |
| CVE-2020-27218 | jetty: buffer not correctly recycled in Gzip Request inflation | MEDIUM | 4.8 | Nov 28, 2020 |
| CVE-2019-12399 | kafka: Connect REST API exposes plaintext secrets in tasks endpoint | HIGH | 7.5 | Jan 14, 2020 |
| CVE-2018-17196 | kafka: potential to bypass transaction/idempotent ACL checks | HIGH | 8.8 | Jul 11, 2019 |
| CVE-2018-1288 | kafka: Users can perform Broker actions via crafted fetch requests, interfering with data replication and causing data lass | MEDIUM | 5.4 | Jul 26, 2018 |
| CVE-2017-12610 | kafka: Clients authenticated with SASL/PLAIN or SASL/SCRAM can impersonate other users | MEDIUM | 6.8 | Jul 26, 2018 |
Showing 1 to 17 of 17 CVEs