Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
apache kafka vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2018-17196
In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users sh...
Apache Kafka
1 Github repository
6.8
CVSSv3
CVE-2017-12610
In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations in Apache Kafka.
Apache Kafka
1 Github repository
7.5
CVSSv3
CVE-2022-34917
A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated clients to allocate large amounts of memory on brokers. This can lead to brokers hitting OutOfMemoryException and causing denial o...
Apache Kafka
8.8
CVSSv3
CVE-2023-25194
A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which has been ...
Apache Kafka Connect
1 Metasploit module
7 Github repositories
7.8
CVSSv3
CVE-2023-34040
In Spring for Apache Kafka 3.0.9 and previous versions and versions 2.9.10 and previous versions, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deser...
Vmware Spring For Apache Kafka
1 Github repository
6.3
CVSSv4
CVE-2025-30677
Apache Pulsar contains multiple connectors for integrating with Apache Kafka. The Pulsar IO Apache Kafka Source Connector, Sink Connector, and Kafka Connect Adaptor Sink Connector log sensitive configuration properties in plain text in application logs. This vulnerability can lea...
Apache Software Foundation Apache Pulsar Io Kafka Connector
Apache Software Foundation Apache Pulsar Io Kafka Connect Adaptor
8.8
CVSSv3
CVE-2018-12413
The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition contains a vulnerability...
Tibco Messaging - Apache Kafka Distribution - Schema Repository 1.0.0
5.9
CVSSv3
CVE-2024-8285
A flaw was found in Kroxylicious. When establishing the connection with the upstream Kafka server using a TLS secured connection, Kroxylicious fails to properly verify the server's hostname, resulting in an insecure connection. For a successful attack to be performed, the at...
Red Hat Streams For Apache Kafka 2.8.0
Red Hat Streams For Apache Kafka
Redhat Kroxylicious -
5.3
CVSSv3
CVE-2024-56128
Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Salted Challenge Response Authentication Mechanism (SCRAM) did not fully adhere to the requirements of RFC 5802 [1]. Specific...
Apache Software Foundation Apache Kafka
7.5
CVSSv3
CVE-2019-12399
When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration ...
Apache Kafka 2.0.0
Apache Kafka 2.0.1
Apache Kafka 2.1.0
Apache Kafka 2.1.1
Apache Kafka 2.2.0
Apache Kafka 2.2.1
Apache Kafka 2.3.0
Oracle Banking Corporate Lending Process Management 14.1.0
Oracle Banking Corporate Lending Process Management 14.3.0
Oracle Banking Corporate Lending Process Management 14.4.0
Oracle Banking Credit Facilities Process Management 14.1.0
Oracle Banking Credit Facilities Process Management 14.3.0
Preferred Score:
CVSSv3
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
CVE-2025-46541
gopiplus@hotmail.com
CVE-2025-46461
privilege
CVE-2025-46473
CVE-2025-30406
trân minh-quân
XSS
deserialization
CVE-2025-46507
wp filter post category
CVE-2025-21204
padam shankhadev
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
NEXT »