PT-2025-40602 · Karapace · Karapace

Dugong42

·

Published

2025-10-03

·

Updated

2025-10-04

·

CVE-2025-61673

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:L
Name of the Vulnerable Software and Affected Versions Karapace versions 5.0.0 through 5.0.1
Description Karapace, an open-source implementation of Kafka REST and Schema Registry, has an issue where authentication checks are bypassed when OAuth 2.0 Bearer Token authentication is enabled. Specifically, if a request does not include an 'Authorization' header, the token validation process is skipped. This allows unauthorized access to Schema Registry endpoints that should require authentication, effectively disabling the OAuth authentication mechanism.
Recommendations Update to version 5.0.2 or later.

Exploit

Fix

Missing Authentication

Authentication Bypass Using an Alternate Path or Channel

Weakness Enumeration

Related Identifiers

CVE-2025-61673
GHSA-VQ25-VCRW-GJ53

Affected Products

Karapace