Skip to content
Apache KafkaGHSA-3j6g-hxx5-3q26

Observable Discrepancy in Apache Kafka

Medium5.9CVE-2021-38153 · Published Sep 23, 2021 · updated Aug 7, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
org.apache.kafka:kafka-clients
Maven
>= 2.0.0, < 2.6.32.6.3
>= 2.7.0, < 2.7.22.7.2
>= 2.8.0, < 2.8.12.8.1
org.apache.kafka:kafka_2.13
Maven
>= 2.4.0, < 2.6.32.6.3
>= 2.7.0, < 2.7.22.7.2
>= 2.8.0, < 2.8.12.8.1
Details and references

Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected versions include Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.4.1, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.7.0, 2.7.1, and 2.8.0.

CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-203
Also known as
BIT-kafka-2021-38153, CVE-2021-38153

More Apache Kafka advisories

All Apache Kafka
DateAdvisory
May 132022Improper Authentication in Apache Kafka
CVE-2017-12610Medium6.8fixed in 0.10.2.2, 0.11.0.2
Nov 192024Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider
CVE-2024-31141Medium6.5fixed in 3.7.1
Dec 182024Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm
CVE-2024-56128Low5.3fixed in 3.7.2, 3.8.1
Jun 102025Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
CVE-2025-27817Medium7.5fixed in 3.9.1
Jun 102025Apache Kafka Deserialization of Untrusted Data vulnerability
CVE-2025-27818High8.8fixed in 3.9.1
Jun 102025Apache Kafka Deserialization of Untrusted Data vulnerability
CVE-2025-27819High8.8fixed in 3.4.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.