Apache KafkaGHSA-3j6g-hxx5-3q26
Observable Discrepancy in Apache Kafka
Medium5.9CVE-2021-38153 · Published Sep 23, 2021 · updated Aug 7, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| org.apache.kafka:kafka-clients Maven | >= 2.0.0, < 2.6.3 | 2.6.3 |
| >= 2.7.0, < 2.7.2 | 2.7.2 | |
| >= 2.8.0, < 2.8.1 | 2.8.1 | |
| org.apache.kafka:kafka_2.13 Maven | >= 2.4.0, < 2.6.3 | 2.6.3 |
| >= 2.7.0, < 2.7.2 | 2.7.2 | |
| >= 2.8.0, < 2.8.1 | 2.8.1 |
Details and references
Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-203
- Also known as
- BIT-kafka-2021-38153, CVE-2021-38153
- nvd.nist.gov/vuln/detail/CVE-2021-38153
- github.com/apache/kafka
- kafka.apache.org/cve-list
- lists.apache.org/thread.html/r26390c8b09ecfa356582d665b0c01f4cdcf16ac047c85f9f9f06a88c@%3Cdev.kafka.apache.org%3E
- lists.apache.org/thread.html/r26390c8b09ecfa356582d665b0c01f4cdcf16ac047c85f9f9f06a88c@%3Cusers.kafka.apache.org%3E
- lists.apache.org/thread.html/r35322aec467ddae34002690edaa4d9f16e7df9b5bf7164869b75b62c@%3Cdev.kafka.apache.org%3E
- lists.apache.org/thread.html/r45cc0602d5f2cbb72e48896dfadf5e5b87ed85630449598b40e8f0be@%3Cdev.kafka.apache.org%3E
- lists.apache.org/thread.html/r45cc0602d5f2cbb72e48896dfadf5e5b87ed85630449598b40e8f0be@%3Cusers.kafka.apache.org%3E
- lists.apache.org/thread.html/rd9ef217b09fdefaf32a4e1835b59b96629542db57e1f63edb8b006e6@%3Cdev.kafka.apache.org%3E
- lists.apache.org/thread.html/rd9ef217b09fdefaf32a4e1835b59b96629542db57e1f63edb8b006e6@%3Cusers.kafka.apache.org%3E
- support.confluent.io/hc/en-us/articles/4407632156692-CVE-2021-38153-Confluent-Platform-Vulnerability-Timing-attacks
- www.oracle.com/security-alerts/cpuapr2022.html
- www.oracle.com/security-alerts/cpujan2022.html
- www.oracle.com/security-alerts/cpujul2022.html
More Apache Kafka advisories
All Apache Kafka| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 132022 | Improper Authentication in Apache Kafka CVE-2017-12610Medium6.8fixed in 0.10.2.2, 0.11.0.2 | Medium6.8 | 0.10.2.2, 0.11.0.2 |
| Nov 192024 | Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider CVE-2024-31141Medium6.5fixed in 3.7.1 | Medium6.5 | 3.7.1 |
| Dec 182024 | Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm CVE-2024-56128Low5.3fixed in 3.7.2, 3.8.1 | Low5.3 | 3.7.2, 3.8.1 |
| Jun 102025 | Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability CVE-2025-27817Medium7.5fixed in 3.9.1 | Medium7.5 | 3.9.1 |
| Jun 102025 | Apache Kafka Deserialization of Untrusted Data vulnerability CVE-2025-27818High8.8fixed in 3.9.1 | High8.8 | 3.9.1 |
| Jun 102025 | Apache Kafka Deserialization of Untrusted Data vulnerability CVE-2025-27819High8.8fixed in 3.4.0 | High8.8 | 3.4.0 |