Apache Kafka security advisories
10 advisories · 2 critical or high in 12 months · latest Apr 20
10 advisories
| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Apr 20 | Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation CVE-2026-33557Critical9.1fixed in 4.1.2 | Critical9.1 | 4.1.2 |
| Apr 20 | Apache Kafka exposes sensitive information in its DEBUG logs CVE-2026-33558Medium5.3fixed in 3.9.2, 4.0.1 | Medium5.3 | 3.9.2, 4.0.1 |
| Apr 7 | Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition CVE-2026-35554High8.7fixed in 3.9.2, 4.0.2, 4.1.2 | High8.7 | 3.9.2, 4.0.2, 4.1.2 |
| Jun 102025 | Apache Kafka Deserialization of Untrusted Data vulnerability CVE-2025-27818High8.8fixed in 3.9.1 | High8.8 | 3.9.1 |
| Jun 102025 | Apache Kafka Deserialization of Untrusted Data vulnerability CVE-2025-27819High8.8fixed in 3.4.0 | High8.8 | 3.4.0 |
| Jun 102025 | Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability CVE-2025-27817Medium7.5fixed in 3.9.1 | Medium7.5 | 3.9.1 |
| Dec 182024 | Apache Kafka's SCRAM implementation Incorrectly Implements Authentication Algorithm CVE-2024-56128Low5.3fixed in 3.7.2, 3.8.1 | Low5.3 | 3.7.2, 3.8.1 |
| Nov 192024 | Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider CVE-2024-31141Medium6.5fixed in 3.7.1 | Medium6.5 | 3.7.1 |
| May 132022 | Improper Authentication in Apache Kafka CVE-2017-12610Medium6.8fixed in 0.10.2.2, 0.11.0.2 | Medium6.8 | 0.10.2.2, 0.11.0.2 |
| Sep 232021 | Observable Discrepancy in Apache Kafka CVE-2021-38153Medium5.9fixed in 2.6.3, 2.7.2, 2.8.1 | Medium5.9 | 2.6.3, 2.7.2, 2.8.1 |
About Apache Kafka
Distributed event streaming.
Packages watched: org.apache.kafka:kafka-clients (Maven), org.apache.kafka:kafka_2.13 (Maven).