CVE-2026-33558Disclosure(apache / kafka)

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the sensitive information will be exposed via the requests and responses output log. The entire lists of impacted requests and responses are: * AlterConfigsRequest * AlterUserScramCredentialsRequest * ExpireDelegationTokenRequest * IncrementalAlterConfigsRequest * RenewDelegationTokenRequest * SaslAuthenticateRequest * createDelegationTokenResponse * describeDelegationTokenResponse * SaslAuthenticateResponse This issue affects Apache Kafka: from any version supported the listed API above through v3.9.1, v4.0.0. We advise the Kafka users to upgrade to v3.9.2, v4.0.1, or later to avoid this vulnerability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-533

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kafka

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-17); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
kafka

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-17: 1Mentions · 2026-04-19: 1Mentions · 2026-04-21: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-21: 104-1704-1904-21
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Full discourse3 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-33557, and CVE-2026-33558: Vulnerabilities in Apache Kafka, up to 9.1 rating 🔥 Two new vulnerabilities in Apache Kafka: the first allows attacker to generate their own JWT from any issuer, the second flow is the sensitive information disclosure, if the NetworkClient component is set to the DEBUG log level. 👉 https://nt.ls/M6oTa

    Post summary

    Apache Kafka is exposed to two new CVEs: one enables attackers to forge JWTs, while the other leaks sensitive information if DEBUG logging is enabled; the vulnerabilities are rated up to 9.1.

    06044786
    7.6K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-33557: Apache Kafka: Missing JWT token validation in OAUTHBEARER authentication https://www.openwall.com/lists/oss-security/2026/04/17/2 CVE-2026-33558: Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output https://www.openwall.com/lists/oss-security/2026/04/17/3

    Post summary

    Two new Apache Kafka CVEs are disclosed: one involving missing JWT validation and another exposing information via log output.

    00000209
    4.5K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33558 CVE-2026-33558 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33558

    Post summary

    The text merely references CVE-2026-33558 with a link to a vulnerability details page, providing no further technical information, PoC, or exploitation status.

    0000029
    4.0K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Appapachekafka---
Appapachekafka4.0.0--
Appapachekafka4.0.0--
Appapachekafka4.0.0--
Appapachekafka4.0.0--

Explore more