
CVE-2026-33557, and CVE-2026-33558: Vulnerabilities in Apache Kafka, up to 9.1 rating 🔥 Two new vulnerabilities in Apache Kafka: the first allows attacker to generate their own JWT from any issuer, the second flow is the sensitive information disclosure, if the NetworkClient component is set to the DEBUG log level. 👉 https://nt.ls/M6oTa
Post summary
Apache Kafka is exposed to two new CVEs: one enables attackers to forge JWTs, while the other leaks sensitive information if DEBUG logging is enabled; the vulnerabilities are rated up to 9.1.


