ZoomEye[verified]@zoomeye_teamDisclosure
The tweet announces CVE-2026-33557—a critical missing JWT token validation flaw in Kafka’s OAUTHBEARER authentication—linking to a detailed DarkEye analysis and noting 9,000 globally exposed instances.
Netlas.io[verified]@Netlas_ioDisclosure
Two newly disclosed Apache Kafka vulnerabilities: one permits JWT forgery from any issuer, and the other leaks sensitive data when the NetworkClient component logs at DEBUG level.
Upwind Security MDR[verified]@UpwindMDRPatch
This tweet alerts to an auth bypass in Apache Kafka (CVE‑2026‑33557) caused by missing JWT validation and urges users to upgrade to 4.1.2+ or enforce JWT checks immediately.
Giuseppe `N3mes1s`[verified]@N3mes1sDisclosure
The tweet points out a new CVE for Apache Kafka involving missing JWT token validation in OAUTHBEARER authentication, but provides no PoC, exploit, patch, or evidence of real‑world attacks.
Gray Hats@the_yellow_fallPatch
Apache Kafka CVE-2026-33557 is an OAUTHBEARER bypass with logging leaks; patching to v4.1.2 or v4.2.0 is advised.
CCB Alert@CCBalertDisclosure
The short warning labels CVE-2026-33557 as a critical flaw in Apache Kafka with a high CVSS score and potential confidentiality impact, but offers no exploit details or patch information.
PulsePatch.io@pulsepatchioPatch
The post highlights a critical Apache Kafka OAUTHBEARER authentication flaw (CVE-2026-33557) that could allow JWT bypass and advises reviewing configurations and applying patches promptly.
Open Source Security mailing list@oss_securityDisclosure
Two new CVEs affecting Apache Kafka were announced, detailing a missing JWT token validation issue and information exposure via client log output.