Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
Maven/org.apache.kafka:kafka-clients — 7 CVEs · VulnScope
pkg:Maven/
org.apache.kafka:kafka-clients
7 total CVEs
CRITICAL
1
HIGH
2
MEDIUM
4
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.1
CVE-2026-33557
Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
>= 4.1.0, < 4.1.2
HIGH
8.7
CVE-2026-35554
Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
>= 2.8.0, < 3.9.2
HIGH
7.5
CVE-2025-27817
Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
>= 3.1.0, < 3.9.1
MEDIUM
6.8
Improper Authentication in Apache Kafka
>= 0.10.0.0, < 0.10.2.2
MEDIUM
6.5
Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider
>= 2.3.0, < 3.7.1
MEDIUM
5.9
Observable Discrepancy in Apache Kafka
>= 2.0.0, < 2.6.3
MEDIUM
5.3
Apache Kafka exposes sensitive information in its DEBUG logs
>= 0.11.0, < 3.9.2
CVE-2017-12610
CVE-2024-31141
CVE-2021-38153
CVE-2026-33558