PT-2026-33644 · Apache · Apache Kafka

Published

2026-04-19

·

Updated

2026-04-22

·

CVE-2026-33558

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Kafka versions prior to 3.9.2 Apache Kafka versions prior to 4.0.1
Description The NetworkClient component outputs complete request and response information when the log level is set to DEBUG. While the default log level is INFO, enabling DEBUG exposes sensitive data through the logs. Impacted requests and responses include 'AlterConfigsRequest', 'AlterUserScramCredentialsRequest', 'ExpireDelegationTokenRequest', 'IncrementalAlterConfigsRequest', 'RenewDelegationTokenRequest', 'SaslAuthenticateRequest', 'createDelegationTokenResponse', 'describeDelegationTokenResponse', and 'SaslAuthenticateResponse'.
Recommendations Upgrade to version 3.9.2 or later. Upgrade to version 4.0.1 or later. As a temporary workaround, ensure the log level for the NetworkClient component is not set to DEBUG.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-KAFKA-2026-33558
CVE-2026-33558
GHSA-WF66-MPHR-4C4R

Affected Products

Apache Kafka