Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

51 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.4)0.20%—Confluent Kafka Python ClientAI1/10/20261/10/2026
Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.
Pendiente de análisisMedia (6.5)0.36%—Apache KafkaAIStreamshub Console FOR Apache KafkaAI28/9/202630/9/2026
A flaw was found in the StreamsHub Console for Apache Kafka. Tenant-supplied Kafka client properties from the Console custom resource are copied into the console-api AdminClient configuration without filtering security-sensitive keys, allowing a Console CR author to set config.providers and bootstrap.servers to…
AnalizadaAlta (8.8)1.2%—Apache-airflow-providers-apache-kafka16/9/202618/9/2026
Apache Airflow Apache Kafka provider versions 1.15.0 before 2.0.0 resolve dotted-path strings found in a Kafka connection's `extra` field into Python callables via `import_string`, with no allowlist, and hand them to the confluent-kafka client which invokes them. Deployments that have enabled the Kafka event producer…
Pendiente de análisisMedia (5.4)0.25%—Apache KafkaAILinuxfoundation StrimziAI15/9/202630/9/2026
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, deploying only the Topic Operator or only the User Operator through the Kafka custom resource leaves the Entity Operator ServiceAccount with RBAC permissions for both…
Pendiente de análisisAlta (8)0.29%—Apache KafkaAILinuxfoundation StrimziAI15/9/202630/9/2026
Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. In Strimzi 1.0.0 and earlier, an attacker who can create a Kafka custom resource can set Kafka.spec.entityOperator watchedNamespace to a target namespace, causing the Cluster Operator to create a Role…
AnalizadaMedia (6.5)0.42%—Vmware Spring FOR Apache Kafka27/8/20264/9/2026
DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and passes its raw bytes directly to new BigInteger(header.value()) with no length or format validation. Spring for Apache Kafka 4.1.0 Spring for Apache Kafka 4.0.0 - 4.0.6 Spring for Apache Kafka 3.0.0…
AnalizadaMedia (6.5)0.27%—Vmware Spring FOR Apache Kafka27/8/20261/9/2026
JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these mappers are used — which is the default configuration for all @KafkaListener consumers — an external Kafka producer can inject a java.net.InetAddress type via the spring_json_header_types message…
AplazadaBaja (2.1)0.41%—Provectus Kafka-uiAI24/8/202626/8/2026
A security flaw has been discovered in provectus kafka-ui up to 0.7.2. The affected element is the function executeSmartFilterTest of the file kafka-ui-api/src/main/java/com/provectus/kafka/ui/controller/MessagesController.java of the component Groovy Code Handler. The manipulation results in code injection. The…
AnalizadaAlta (7.4)0.24%—Splunk Connect FOR Kafka19/8/202624/8/2026
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent from the connector when Kerberos authentication is used with Hypertext Transfer Protocol (HTTP) Event Collector in Splunk Enterprise. The vulnerability is possible because…
AnalizadaAlta (8.2)0.41%—Splunk Connect FOR Kafka19/8/202624/8/2026
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure a non-secure Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise that causes the connector to send authentication credentials…
AnalizadaMedia (5.9)0.38%—Splunk Connect FOR Kafka19/8/202624/8/2026
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API could configure timestamp extraction with a crafted regular expression and matching event data to block a Kafka Connect worker thread, stopping event delivery for the…
AnalizadaMedia (5.9)0.38%—Splunk Connect FOR Kafka19/8/202624/8/2026
In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API and influence responses from a Hypertext Transfer Protocol (HTTP) Event Collector endpoint in Splunk Enterprise could cause the connector to retry failed event batches…
AplazadaBaja (1.9)1.2%—Kino-kafkaesque Ssh-mcp-serverAI6/8/202612/8/2026
A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of the file src/index.ts of the component SSH Command Handler. Performing a manipulation of the argument host/username results in command injection. The attack requires a…
ModificadaAlta (8.7)0.52%—Dpkp Kafka-python10/6/202610/9/2026
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the client event loop by supplying an excessively large iteration count. In scram.py, ScramClient.process_server_first_message() passes the…
AnalizadaAlta (8.7)0.35%—Dpkp Kafka-python10/6/202623/7/2026
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length value without bounds validation. Attackers can send a specially crafted frame…
AnalizadaAlta (8.1)0.65%—Vmware Spring FOR Apache KafkaRedhat FuseRedhat Jboss Enterprise Application Platform Expansion Pack10/6/20265/8/2026
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Combined with Jackson's default bean deserialization, a producer could supply crafted header values that…
AnalizadaMedia (6.5)0.42%—Vmware Spring FOR Apache Kafka10/6/202623/7/2026
Spring Kafka's retry topic infrastructure did not sufficiently validate user-controlled header values before acting on them. A producer could send a record with a crafted retry_topic-attempts header to supply an out-of-range attempt count and cause the retry topic router to misidentify where the message was in the…
AnalizadaMedia (6.5)0.42%—Vmware Spring FOR Apache Kafka10/6/202623/7/2026
When an application opts into DelegatingDeserializer, a producer can grow the consumer's heap without bound by sending records with unique random spring.kafka.serialization.selector header values, eventually causing GC thrash and OutOfMemoryError. Affected versions: Spring for Apache Kafka 4.0.0 through 4.0.5; 3.3.0…
AplazadaMedia (6.9)0.42%—Apache KafkaAIAiven KlawAI2/6/202622/7/2026
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control allows disclosure of password hash. This issue has been patched in version 2.10.4.
AplazadaBaja (2.7)0.40%—Apache KafkaAIAiven KlawAI2/6/202622/7/2026
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registration and login mechanisms due to inconsistent handling of username case sensitivity, leading to a targeted Denial of Service (DoS) and complete account lockout. This issue…
AnalizadaMedia (4.3)0.45%—Apache Kafka2/6/202622/7/2026
An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka documentation and the KIP-848. This discrepancy can result…
AplazadaMedia (6.5)0.48%—Microsoft Kafka Sink Azure KustoAIApache KafkaAIMicrosoft Azure Data ExplorerAI11/5/202617/6/2026
kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the kusto.tables.topics.mapping configuration. The db, table, mapping, and format fields of each mapping entry were…
AnalizadaMedia (5.3)0.89%—Apache Kafka20/4/202617/6/2026
Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the sensitive information will be exposed via the…
ModificadaCrítica (9.1)0.93%—Apache Kafka20/4/202615/7/2026
A possible security vulnerability has been identified in Apache Kafka. By default, the broker property `sasl.oauthbearer.jwt.validator.class` is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`. It accepts any JWT token without validating its signature, issuer, or audience. An attacker can…
AnalizadaAlta (8.7)0.65%—Apache Kafka7/4/202617/8/2026
A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still in flight, the batch’s ByteBuffer is prematurely deallocated…