VendorsApachekafkaany version
Vulnerabilities

Apache Software Foundation Kafka any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

15CVEs
CVE-2026-33557
Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication
Published 2026-04-20 · Modified
9.1EPSS 0.009
CVE-2018-17196
In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where this vulnerability has been fixed.
Published 2019-07-11 · Modified
8.8EPSS 0.055
CVE-2025-27818
Apache Kafka: Possible RCE attack via SASL JAAS LdapLoginModule configuration
Published 2025-06-10 · Analyzed
8.8EPSS 0.010
CVE-2026-35554
Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
Published 2026-04-07 · Analyzed
8.7EPSS 0.006
CVE-2025-27817
Apache Kafka Client: Arbitrary file read and SSRF vulnerability
Published 2025-06-10 · Analyzed
7.5EPSS 0.688
CVE-2022-34917
Unauthenticated clients may cause OutOfMemoryError on Apache Kafka Brokers
Published 2022-09-20 · Modified
7.5EPSS 0.015
CVE-2025-27819
Apache Kafka: Possible RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration
Published 2025-06-10 · Analyzed
7.5EPSS 0.010
CVE-2024-27309
Apache Kafka: Potential incorrect access control during migration from ZK mode to KRaft mode
Published 2024-04-12 · Analyzed
7.4EPSS 0.011
CVE-2017-12610
In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations in Apache Kafka.
Published 2018-07-26 · Modified
6.8EPSS 0.030
CVE-2024-31141
Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider
Published 2024-11-19 · Analyzed
6.5EPSS 0.012
CVE-2021-38153
Timing Attack Vulnerability for Apache Kafka Connect and Clients
Published 2021-09-22 · Modified
5.9EPSS 0.063
CVE-2018-1288
In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.
Published 2018-07-26 · Modified
5.5EPSS 0.048
CVE-2026-33558
Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output
Published 2026-04-20 · Analyzed
5.3EPSS 0.009
CVE-2024-56128
Apache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryption
Published 2024-12-18 · Analyzed
5.3EPSS 0.008
CVE-2026-41115
Apache Kafka: Improper Authorization in CONSUMER_GROUP_DESCRIBE API
Published 2026-06-02 · Analyzed
4.3EPSS 0.005