Skip to content
Apache KafkaGHSA-28jg-cgg7-j4wc

Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation

Critical9.1CVE-2026-33557 · Published Apr 20, 2026 · updated Sep 10, 2026

A security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without validating its signature, issuer, or audience. An attacker can generate a JWT token from any issuer with the `preferred_username` set to any user, and the broker will accept it. Apache advises Kafka users using kafka v4.1.0 or v4.1.1 to set the config `sasl.oauthbearer.jwt.validator.class` to `org.apache.kafka.common.security.oauthbearer.BrokerJwtValidator` explicitly to avoid this vulnerability. Since Kafka v4.1.2 and v4.2.0 and later, the issue is fixed and will correctly validate the JWT token.

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.kafka:kafka-clients
Maven
>= 4.1.0, < 4.1.24.1.2
Details and references

More Apache Kafka advisories

All Apache Kafka

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.