CVE-2026-27133Patch(linuxfoundation / strimzi)

LOWCVSS 5.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch linuxfoundation strimzi systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 to before 0.50.1, when a chain consisting of multiple CA (Certificate Authority) certificates is used in the trusted certificates configuration of a Kafka Connect operand or of the target cluster in the Kafka MirrorMaker 2 operand, all of the certificates that are part of the CA chain will be trusted individually when connecting to the Apache Kafka cluster. Due to this error, the affected operand (Kafka Connect or Kafka MirrorMaker 2) might accept connections to Kafka brokers using server certificates signed by one of the other CAs in the CA chain and not just by the last CA in the chain. This issue is fixed in Strimzi 0.50.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-295CWE-296

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • strimzi

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
strimzi

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Patch / Workaround · 2026-02-19: 102-1902-20
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-02-191
Patch1
2026-02-201
Disclosure1
Full discourse2 posts
  • Strimzi@strimziio
    Patch

    We have released #Strimzi 0.50.1. This patch release addresses a few minor bug fixes and dependency updates. It also fixes two new Strimzi CVEs: CVE-2026-27133 and CVE-2026-27134! Please check the new release and the CVEs, and upgrade if needed: ➡️ https://github.com/strimzi/strimzi-kafka-operator/releases/tag/0.50.1

    Post summary

    The post announces a Strimzi 0.50.1 patch release that fixes CVE‑2026‑27133 and CVE‑2026‑27134 and urges users to upgrade.

    02110299
    2.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27133 Strimzi provides a way to run an Apache Kafka cluster on Kubernetes or OpenShift in various deployment configurations. From 0.47.0 to before 0.50.1, when a chain cons… https://www.cve.org/CVERecord?id=CVE-2026-27133

    Post summary

    The text cites CVE-2026-27133 and indicates affected Strimzi versions but lacks PoC, exploit, active exploitation, patch, or detailed technical information, making it a basic disclosure.

    0000071
    56.4K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Applinuxfoundationstrimzi---

Explore more