PT-2026-20655 · Red Hat+2 · Openshift+3

Scholzj

·

Publicado

2026-02-19

·

Atualizado

2026-02-25

·

CVE-2026-27134

CVSS v3.1

8.1

Alta

VetorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Strimzi versions 0.49.0 through 0.50.0
Description Strimzi allows running an Apache Kafka cluster on Kubernetes or OpenShift. Versions 0.49.0 through 0.50.0 incorrectly configure trusted certificates for mTLS authentication when using a custom Cluster or Clients CA with a multistage CA chain. This allows users with certificates signed by any CA in the chain to authenticate. The issue only affects users utilizing a custom Cluster or Clients CA with a multistage CA chain and does not impact those using Strimzi-managed CAs or a single custom CA.
Recommendations Versions 0.49.0 through 0.50.0: Upgrade to version 0.50.1 or later. Versions 0.49.0 through 0.50.0: Provide only the single CA that should be used instead of the full CA chain as the custom CA.

Exploit

Correção

Improper Authentication

Improper Certificate Validation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-27134
GHSA-2QWX-RQ6J-8R6J

Produtos afetados

Apache Kafka
Kubernetes
Openshift
Strimzi