PT-2026-33644 · Apache · Apache Kafka
Published
2026-04-19
·
Updated
2026-04-22
·
CVE-2026-33558
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Kafka versions prior to 3.9.2
Apache Kafka versions prior to 4.0.1
Description
The NetworkClient component outputs complete request and response information when the log level is set to DEBUG. While the default log level is INFO, enabling DEBUG exposes sensitive data through the logs. Impacted requests and responses include 'AlterConfigsRequest', 'AlterUserScramCredentialsRequest', 'ExpireDelegationTokenRequest', 'IncrementalAlterConfigsRequest', 'RenewDelegationTokenRequest', 'SaslAuthenticateRequest', 'createDelegationTokenResponse', 'describeDelegationTokenResponse', and 'SaslAuthenticateResponse'.
Recommendations
Upgrade to version 3.9.2 or later.
Upgrade to version 4.0.1 or later.
As a temporary workaround, ensure the log level for the NetworkClient component is not set to DEBUG.
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Kafka