Apache Kafka是美国阿帕奇(Apache)基金会的一套开源的分布式流媒体平台。该平台能够获取实时数据,用于构建对数据流的变化进行实时反应的应用程序。 Apache Kafka 3.9.1及之前版本、4.0.1及之前版本和4.1.1及之前版本存在安全漏洞,该漏洞源于Java生产者客户端缓冲区池管理中的竞争条件,可能导致消息被静默传递到错误的主题,从而泄露敏感数据或导致下游数据处理错误。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Kafka Clients | 2.8.0 ~ 3.9.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-34197 | Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Authenticated users could pe | |
| CVE-2026-33227 | Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ Web, | |
| CVE-2026-27314 | Apache Cassandra: Privilege escalation via ADD IDENTITY authorization bypass | |
| CVE-2026-27315 | Apache Cassandra: cqlsh history sensitive information leak | |
| CVE-2026-32588 | Apache Cassandra: Authenticated DoS via ALTER ROLE Password Hashing |
No comments yet