Known vulnerabilities in Apache Kafka

Software: Apache Kafka
Software CPE: cpe:2.3:a:apache_foundation:apache_kafka:*:*:*:*:*:*:*:*
Total vulnerabilities: 27
Public exploits: 3
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Apache Kafka Apache Kafka is affected by 27 known vulnerabilities: 5 high, 15 medium, 7 low Critical High Medium Low

Vulnerabilities (27)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU137737 - Information Exposure Through Log Files
CVE-2026-33558
CWE-532 Medium
No
No
3.9.2, 4.0.1 15.07.2026 SB2026071548
SB2026071553
SB2026080425
#VU133398 - Incorrect Authorization
CVE-2026-41115
CWE-863 Low
No
No
4.3.0 04.06.2026 SB20260604101
SB2026080308
#VU132004 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE-2026-35554
CWE-362 High
No
No
3.9.2, 4.0.2, 4.1.2, 4.2.0 21.05.2026 SB2026052106
SB2026052107
SB2026052541
and 5 more
#VU114434 - Deserialization of Untrusted Data
CVE-2025-27819
CWE-502 High
No
No
3.4.0 26.08.2025 SB2025082612
SB2025082623
SB2025100118
and 4 more
#VU112255 - Deserialization of Untrusted Data
CVE-2025-27818
CWE-502 Medium
No
No
3.9.1 04.07.2025 SB20250704102
SB2025070708
SB2025080519
and 16 more
#VU112146 - Server-Side Request Forgery (SSRF)
CVE-2025-27817
CWE-918 High
Available
No
3.9.1 03.07.2025 SB2025070339
SB2025070340
SB2025070345
and 42 more
#VU101829 - Improper Authentication
CVE-2024-56128
CWE-287 Medium
No
No
3.7.2, 3.8.1 18.12.2024 SB2024121826
SB2025041647
SB2025041651
and 12 more
#VU95166 - Incorrect Authorization
CVE-2024-27309
CWE-863 Medium
No
No
3.6.2 02.08.2024 SB2024080227
SB2024080228
SB20240827147
and 5 more
#VU72123 - Deserialization of Untrusted Data
CVE-2023-25194
CWE-502 Low
Available
No
3.4.0 11.02.2023 SB2023021101
SB2023030952
SB2023040419
and 40 more
#VU67489 - Resource exhaustion
CVE-2022-34917
CWE-400 Medium
No
No
2.8.2, 3.0.2, 3.1.2, 3.2.3 20.09.2022 SB2022092020
SB2022100556
SB2022110304
and 21 more
#VU56790 - Information Exposure Through Timing Discrepancy
CVE-2021-38153
CWE-208 Low
No
No
2.8.1 21.09.2021 SB2021092116
SB2022010906
SB2022012104
and 21 more
#VU24240 - Exposure of sensitive information to an unauthorized actor
CVE-2019-12399
CWE-200 Low
No
No
2.2.2, 2.3.1 14.01.2020 SB2020011418
SB2020032709
SB2021012208
and 14 more
#VU21580 - Improper input validation
CVE-2019-16942
CWE-20 Medium
No
No
2.2.2, 2.3.1 07.10.2019 SB2019100711
SB2019100716
SB2019111903
and 23 more
#VU21136 - Exposure of sensitive information to an unauthorized actor
CVE-2019-16335
CWE-200 Medium
No
No
2.2.2, 2.3.1 16.09.2019 SB2019091616
SB2019100716
SB2019102422
and 21 more
#VU21135 - Exposure of sensitive information to an unauthorized actor
CVE-2019-14540
CWE-200 Medium
Available
No
2.2.2, 2.3.1 16.09.2019 SB2019091616
SB2019100716
SB2019102422
and 23 more
#VU19941 - Exposure of sensitive information to an unauthorized actor
CVE-2019-12086
CWE-200 Medium
No
No
2.2.2, 2.3.1 06.08.2019 SB2019052407
SB2019092703
SB2019100116
and 29 more
#VU19937 - Exposure of sensitive information to an unauthorized actor
CVE-2019-14439
CWE-200 Medium
No
No
2.2.2, 2.3.1 06.08.2019 SB2019073015
SB2019100716
SB2019102422
and 16 more
#VU19933 - Permissions, Privileges, and Access Controls
CVE-2019-14379
CWE-264 High
No
No
2.2.2, 2.3.1 05.08.2019 SB2019091307
SB2019092703
SB2019100116
and 33 more
#VU19018 - Deserialization of Untrusted Data
CVE-2019-12384
CWE-502 High
No
No
2.2.2, 2.3.1 04.07.2019 SB2019091218
SB2019092703
SB2019100116
and 28 more
#VU18961 - Exposure of sensitive information to an unauthorized actor
CVE-2019-12814
CWE-200 Medium
No
No
2.2.2, 2.3.1 02.07.2019 SB2019062606
SB2019092703
SB2019100116
and 25 more


Showing elements 1 - 20 out of 27