Skip to content

Apache Kafka security advisories

10 advisories · 2 critical or high in 12 months · latest Apr 20

10 advisories

DateAdvisory
Apr 20Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
CVE-2026-33557Critical9.1fixed in 4.1.2
Apr 20Apache Kafka exposes sensitive information in its DEBUG logs
CVE-2026-33558Medium5.3fixed in 3.9.2, 4.0.1
Apr 7Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
CVE-2026-35554High8.7fixed in 3.9.2, 4.0.2, 4.1.2
Jun 102025Apache Kafka Deserialization of Untrusted Data vulnerability
CVE-2025-27818High8.8fixed in 3.9.1
Jun 102025Apache Kafka Deserialization of Untrusted Data vulnerability
CVE-2025-27819High8.8fixed in 3.4.0
Jun 102025Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
CVE-2025-27817Medium7.5fixed in 3.9.1
Dec 182024Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm
CVE-2024-56128Low5.3fixed in 3.7.2, 3.8.1
Nov 192024Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider
CVE-2024-31141Medium6.5fixed in 3.7.1
May 132022Improper Authentication in Apache Kafka
CVE-2017-12610Medium6.8fixed in 0.10.2.2, 0.11.0.2
Sep 232021Observable Discrepancy in Apache Kafka
CVE-2021-38153Medium5.9fixed in 2.6.3, 2.7.2, 2.8.1
About Apache Kafka

Distributed event streaming.

Packages watched: org.apache.kafka:kafka-clients (Maven), org.apache.kafka:kafka_2.13 (Maven).

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.