Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
51 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.42% | — | Linuxfoundation Strimzi Kafka Operator | 21/2/2026 | 15/7/2026 | Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In versions 0.49.0 through 0.50.0, when using a custom Cluster or Clients CA with a multistage CA chain consisting of multiple CAs, Strimzi incorrectly configures the trusted certificates for mTLS… | |
| Aplazada | Alta (7.7) | 0.41% | — | Apache KafkaAIGoogle BigqueryAIAiven Google Bigquery Kafka Connect Sink ConnectorAI | 16/1/2026 | 17/6/2026 | Kafka Connect BigQuery Connector is an implementation of a sink connector from Apache Kafka to Google BigQuery. Prior to 2.11.0, there is an arbitrary file read in Google BigQuery Sink connector. Aiven's Google BigQuery Kafka Connect Sink connector requires Google Cloud credential configurations for authentication to… | |
| Aplazada | Media (6.5) | 0.39% | — | Kafka UIAI | 14/10/2025 | 17/6/2026 | Improper input validation in the component /kafka/ui/serdes/CustomSerdeLoader.java of kafka-ui v0.6.0 to v0.7.2 allows attackers to execute arbitrary code via supplying crafted data. | |
| Aplazada | Alta (7.5) | 0.63% | — | Kafka UI Kafka-uiAI | 14/10/2025 | 17/6/2026 | An issue in the Configure New Cluster interface of kafka-ui v0.6.0 to v0.7.2 allows attackers to cause a Denial of Service (DoS) via uploading a crafted configuration file. | |
| Analizada | Alta (7.5) | 1.0% | — | Apache Kafka | 10/6/2025 | 17/6/2026 | In CVE-2023-25194, we announced the RCE/Denial of service attack via SASL JAAS JndiLoginModule configuration in Kafka Connect API. But not only Kafka Connect API is vulnerable to this attack, the Apache Kafka brokers also have this vulnerability. To exploit this vulnerability, the attacker needs to be able to connect… | |
| Analizada | Alta (8.8) | 1.0% | — | Apache Kafka | 10/6/2025 | 17/6/2026 | A possible security vulnerability has been identified in Apache Kafka. This requires access to a alterConfig to the cluster resource, or Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which has been possible on… | |
| Analizada | Alta (7.5) | 69% | 💥 Exploit | Apache Kafka | 10/6/2025 | 17/6/2026 | A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including "sasl.oauthbearer.token.endpoint.url" and "sasl.oauthbearer.jwks.endpoint.url". Apache Kafka allows… | |
| Aplazada | Alta (8.9) | 0.57% | — | Kafbat UIAIApache KafkaAI | 6/6/2025 | 17/6/2026 | Kafbat UI is a web user interface for managing Apache Kafka clusters. An unsafe deserialization vulnerability in version 1.0.0 allows any unauthenticated user to execute arbitrary code on the server. Version 1.1.0 fixes the issue. | |
| Analizada | Media (5.3) | 0.82% | — | Apache Kafka | 18/12/2024 | 17/6/2026 | Incorrect Implementation of Authentication Algorithm in Apache Kafka's SCRAM implementation. Issue Summary: Apache Kafka's implementation of the Salted Challenge Response Authentication Mechanism (SCRAM) did not fully adhere to the requirements of RFC 5802 [1]. Specifically, as per RFC 5802, the server must verify… | |
| Analizada | Media (6.5) | 1.2% | — | Apache Kafka | 19/11/2024 | 17/6/2026 | Files or Directories Accessible to External Parties, Improper Privilege Management vulnerability in Apache Kafka Clients. Apache Kafka Clients accept configuration data for customizing behavior, and includes ConfigProvider plugins in order to manipulate these configurations. Apache Kafka also provides… | |
| Aplazada | Alta (8.1) | 39% | 💥 PoC | Kafka UIAIApache KafkaAI | 19/6/2024 | 17/6/2026 | Kafka UI is an Open-Source Web UI for Apache Kafka Management. Kafka UI API allows users to connect to different Kafka brokers by specifying their network address and port. As a separate feature, it also provides the ability to monitor the performance of Kafka brokers by connecting to their JMX ports. JMX is based on… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Strimzi MirrormakerAIApache Kafka ConnectAI | 17/6/2024 | 9/7/2026 | Incorrect access control in the Kafka Connect REST API in the STRIMZI Project 0.41.0 and earlier allows an attacker to deny the service for Kafka Mirroring, potentially mirror the topics' content to his Kafka cluster via a malicious connector (bypassing Kafka ACL if it exists), and potentially steal Kafka SASL… | |
| Analizada | Alta (7.4) | 1.1% | — | Apache Kafka | 12/4/2024 | 17/6/2026 | While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions are needed to trigger the bug: 1. The administrator decides to remove an ACL 2. The resource associated with the removed ACL continues to have two or more other ACLs… | |
| Modificada | Alta (7.8) | 2.1% | 💥 PoC | Vmware Spring FOR Apache Kafka | 24/8/2023 | 17/6/2026 | In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Specifically, an… | |
| Modificada | Crítica (9.8) | 0.70% | — | Kafkaui-lite Project Kafkaui-lite | 12/6/2023 | 17/6/2026 | An issue was discovered in freakchicken kafkaUI-lite 1.2.11 allows attackers on the same network to gain escalated privileges for the nodes running on it. | |
| Modificada | Media (5.5) | 0.15% | — | Lightbend Alpakka Kafka | 27/4/2023 | 17/6/2026 | Lightbend Alpakka Kafka before 5.0.0 logs its configuration as debug information, and thus log files may contain credentials (if plain cleartext login is configured). This occurs in akka.kafka.internal.KafkaConsumerActor. | |
| Modificada | Alta (8.8) | 96% | 💥 Exploit | Apache Kafka Connect | 7/2/2023 | 17/6/2026 | A possible security vulnerability has been identified in Apache Kafka Connect API. This requires access to a Kafka Connect worker, and the ability to create/modify connectors on it with an arbitrary Kafka client SASL JAAS config and a SASL-based security protocol, which has been possible on Kafka Connect clusters… | |
| Modificada | Alta (7.5) | 1.5% | — | Apache Kafka | 20/9/2022 | 17/6/2026 | A security vulnerability has been identified in Apache Kafka. It affects all releases since 2.8.0. The vulnerability allows malicious unauthenticated clients to allocate large amounts of memory on brokers. This can lead to brokers hitting OutOfMemoryException and causing denial of service. Example scenarios: - Kafka… | |
| Modificada | Media (5.9) | 6.3% | — | Apache KafkaQuarkusOracle Communications BRM - Elastic Charging EngineOracle Communications Cloud Native Core Policy+4 | 22/9/2021 | 17/6/2026 | Some components in Apache Kafka use `Arrays.equals` to validate a password or key, which is vulnerable to timing attacks that make brute force attacks for such credentials more likely to be successful. Users should upgrade to 2.8.1 or higher, or 3.0.0 or higher where this vulnerability has been fixed. The affected… | |
| Modificada | Media (4.8) | 8.3% | — | Eclipse JettyNetapp Oncommand System ManagerNetapp Snap Creator FrameworkOracle Blockchain Platform+13 | 28/11/2020 | 17/6/2026 | In Eclipse Jetty version 9.4.0.RC0 to 9.4.34.v20201102, 10.0.0.alpha0 to 10.0.0.beta2, and 11.0.0.alpha0 to 11.0.0.beta2, if GZIP request body inflation is enabled and requests from different clients are multiplexed onto a single connection, and if an attacker can send a request with a body that is received entirely… | |
| Modificada | Alta (7.5) | 3.9% | — | Apache KafkaOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Liquidity Management+9 | 14/1/2020 | 17/6/2026 | When Connect workers in Apache Kafka 2.0.0, 2.0.1, 2.1.0, 2.1.1, 2.2.0, 2.2.1, or 2.3.0 are configured with one or more config providers, and a connector is created/updated on that Connect cluster to use an externalized secret variable in a substring of a connector configuration property value, then any client can… | |
| Modificada | Alta (8.8) | 5.5% | — | Apache Kafka | 11/7/2019 | 17/6/2026 | In Apache Kafka versions between 0.11.0.0 and 2.1.0, it is possible to manually craft a Produce request which bypasses transaction/idempotent ACL validation. Only authenticated clients with Write permission on the respective topics are able to exploit this vulnerability. Users should upgrade to 2.1.1 or later where… | |
| Modificada | Alta (8.8) | 0.87% | — | Tibco Messaging - Apache Kafka Distribution - Schema Repository | 6/11/2018 | 17/6/2026 | The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition contains a vulnerability which may allow an attacker to perform… | |
| Modificada | Media (5.4) | 4.8% | — | Apache KafkaRedhat Jboss Middleware Text-only AdvisoriesOracle DatabaseOracle Primavera P6 Enterprise Project Portfolio Management+1 | 26/7/2018 | 17/6/2026 | In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss. | |
| Modificada | Media (6.8) | 2.9% | — | Apache Kafka | 26/7/2018 | 17/6/2026 | In Apache Kafka 0.10.0.0 to 0.10.2.1 and 0.11.0.0 to 0.11.0.1, authenticated Kafka clients may use impersonation via a manually crafted protocol message with SASL/PLAIN or SASL/SCRAM authentication when using the built-in PLAIN or SCRAM server implementations in Apache Kafka. |