Security advisories in the AI and data stack

Severe, 6 weeks2979Projects319
IBMCVE-2026-15911

IBM confluent-kafka: information disclosure

High7.4CVE-2026-15911 · Published Oct 1, 2026 · updated Oct 6, 2026

Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.

IBM advisory

Affected versions

PackageAffectedFixed in
confluent-kafka
Product
<= 2.14.2No fix yet
Details and references

More IBM advisories

All IBM
Advisory
IBM Guardium Data Protection: path traversal
High8.1Sep 29
IBM i: insecure permissions
High7.8Sep 29
IBM DataStage on Cloud Pak for Data: remote code execution
High8.8Sep 29
IBM Guardium Data Protection: command injection
High7.2Sep 29
IBM Guardium Data Protection: command injection
Critical9.1Sep 29
IBM Guardium Data Protection: command injection
High7.5Sep 29