← Vulnerability feed

Vulnerability record · CVE-2026-33558 · published 20 April 2026

CVE-2026-33558: Apache kafka vulnerability

Apache · Kafka

Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the sensitive information will be exposed via the requests and responses output log. The entire lists of impacted requests and responses are: * AlterConfigsRequest * AlterUserScramCredentialsRequest * ExpireDelegationTokenRequest * IncrementalAlterConfigsRequest * RenewDelegationTokenRequest * SaslAuthenticateRequest * createDelegationTokenResponse * describeDelegationTokenResponse * SaslAuthenticateResponse This issue affects Apache Kafka: from any version supported the listed API above through v3.9.1, v4.0.0. We advise the Kafka users to upgrade to v3.9.2, v4.0.1, or later to avoid this vulnerability.

5.3 CVSS 3.1 Medium EPSS 0.89% · top 42.3% CWE-533 · CWE-533
5.3CVSS 3.1 base score
0.89%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the sensitive information will be exposed via the requests and responses output log. The entire lists of impacted requests and responses are: * AlterConfigsRequest * AlterUserScramCredentialsRequest * ExpireDelegationTokenRequest * IncrementalAlterConfigsRequest * RenewDelegationTokenRequest * SaslAuthenticateRequest * createDelegationTokenResponse * describeDelegationTokenResponse * SaslAuthenticateResponse This issue affects Apache Kafka: from any version supported the listed API above through v3.9.1, v4.0.0. We advise the Kafka users to upgrade to v3.9.2, v4.0.1, or later to avoid this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-33558 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.1CVE-2026-33557Apache kafka vulnerabilityA possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set …EPSS 0.93%8.8CVE-2025-27818Apache kafka deserialization of untrusted data vulnerabilityA possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connec…EPSS 1.0%8.8CVE-2018-17196Apache kafka vulnerabilityIn Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL val…EPSS 5.5%8.7CVE-2026-35554Apache kafka race condition vulnerabilityA race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. W…EPSS 0.65%7.5CVE-2025-27817Apache Kafka Client arbitrary file read and SSRF via SASL/OAUTHBEARER URLsApache Kafka Clients accept SASL/OAUTHBEARER configuration values such as sasl.oauthbearer.token.endpoint.url and sasl.oauthbearer.jwks.endpoint.url,…EPSS 69%analysed7.5CVE-2025-27819Apache kafka deserialization of untrusted data vulnerabilityIn CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka…EPSS 1.0%7.5CVE-2022-34917Apache kafka allocation without limits vulnerabilityA security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated…EPSS 1.5%7.5CVE-2019-12399Apache kafka cleartext transmission vulnerabilityWhen Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a conne…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2026-33558), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.