PT-2026-33644 · Apache · Apache Kafka

CVE-2026-33558

·

Published

2026-04-17

·

Updated

2026-07-21

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Kafka versions prior to 3.9.2 Apache Kafka versions prior to 4.0.1
Description The NetworkClient component outputs complete request and response information when the log level is set to DEBUG. While the default log level is INFO, enabling DEBUG exposes sensitive data through the logs. Impacted requests and responses include 'AlterConfigsRequest', 'AlterUserScramCredentialsRequest', 'ExpireDelegationTokenRequest', 'IncrementalAlterConfigsRequest', 'RenewDelegationTokenRequest', 'SaslAuthenticateRequest', 'createDelegationTokenResponse', 'describeDelegationTokenResponse', and 'SaslAuthenticateResponse'.
Recommendations Upgrade to version 3.9.2 or later. Upgrade to version 4.0.1 or later. As a temporary workaround, ensure the log level for the NetworkClient component is not set to DEBUG.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10857
BIT-KAFKA-2026-33558
CLEANSTART-2026-FX60287
CLEANSTART-2026-FZ22182
CLEANSTART-2026-MT41286
CLEANSTART-2026-RU36468
CVE-2026-33558
GHSA-WF66-MPHR-4C4R

Affected Products

Apache Kafka