Known Vulnerabilities for Kafka by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Kafka" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-76403 json | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter ... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-76402 json | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational St... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-76401 json | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational St... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-76400 json | In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational St... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-71576 json | A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming Cloud... | Not Provided | 2026-08-10 | 2026-08-12 |
| CVE-2026-54775 json | CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, a Cor... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-49098 json | Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')... | Not Provided | 2026-07-06 | 2026-07-07 |
| CVE-2026-46584 json | Improper Input Validation, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Camel Mail Comp... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-45080 json | Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control... | Not Provided | 2026-06-02 | 2026-06-02 |
| CVE-2026-44367 json | Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists ... | Not Provided | 2026-06-02 | 2026-06-02 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Kafka | 2.7.0 | |||
| Application | Apache | Kafka | 2.3.1 | |||
| Application | Apache | Kafka | 2.3.0 | |||
| Application | Apache | Kafka | 2.2.2 | |||
| Application | Apache | Kafka | 2.2.1 | |||
| Application | Apache | Kafka | 2.2.0 | |||
| Application | Apache | Kafka | 2.1.2 | |||
| Application | Apache | Kafka | 2.1.1 | |||
| Application | Apache | Kafka | 2.1.0 | |||
| Application | Apache | Kafka | 2.0.2 | |||
| Application | Apache | Kafka | 2.0.1 | |||
| Application | Apache | Kafka | 2.0.0 | |||
| Application | Apache | Kafka | 1.1.1 | |||
| Application | Apache | Kafka | 1.1.0 | |||
| Application | Apache | Kafka | 1.0.2 | |||
| Application | Apache | Kafka | 1.0.1 | |||
| Application | Apache | Kafka | 1.0.0 | |||
| Application | Apache | Kafka | 0.9.0.1 | |||
| Application | Apache | Kafka | 0.9.0.0 | |||
| Application | Apache | Kafka | 0.8.2.2 |