Known Vulnerabilities for Kafka by Apache
Listed below are 10 of the newest known vulnerabilities associated with "Kafka" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-45080 json | Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control... | Not Provided | 2026-06-02 | 2026-06-02 |
| CVE-2026-44367 json | Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists ... | Not Provided | 2026-06-02 | 2026-06-02 |
| CVE-2026-42316 json | kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, k... | Not Provided | 2026-05-11 | 2026-05-11 |
| CVE-2026-41731 json | JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefi... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-41727 json | Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. ... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-41726 json | When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending record... | Not Provided | 2026-06-10 | 2026-06-10 |
| CVE-2026-41115 json | An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRI... | Not Provided | 2026-06-02 | 2026-06-02 |
| CVE-2026-35554 json | A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delive... | Not Provided | 2026-04-07 | 2026-04-07 |
| CVE-2026-33558 json | Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire reque... | Not Provided | 2026-04-20 | 2026-04-20 |
| CVE-2026-33557 json | A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt... | Not Provided | 2026-04-20 | 2026-04-20 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Kafka | 2.7.0 | |||
| Application | Apache | Kafka | 2.3.1 | |||
| Application | Apache | Kafka | 2.3.0 | |||
| Application | Apache | Kafka | 2.2.2 | |||
| Application | Apache | Kafka | 2.2.1 | |||
| Application | Apache | Kafka | 2.2.0 | |||
| Application | Apache | Kafka | 2.1.2 | |||
| Application | Apache | Kafka | 2.1.1 | |||
| Application | Apache | Kafka | 2.1.0 | |||
| Application | Apache | Kafka | 2.0.2 | |||
| Application | Apache | Kafka | 2.0.1 | |||
| Application | Apache | Kafka | 2.0.0 | |||
| Application | Apache | Kafka | 1.1.1 | |||
| Application | Apache | Kafka | 1.1.0 | |||
| Application | Apache | Kafka | 1.0.2 | |||
| Application | Apache | Kafka | 1.0.1 | |||
| Application | Apache | Kafka | 1.0.0 | |||
| Application | Apache | Kafka | 0.9.0.1 | |||
| Application | Apache | Kafka | 0.9.0.0 | |||
| Application | Apache | Kafka | 0.8.2.2 |