CVE-2026-35554Disclosure(apache / kafka)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache kafka systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still in flight, the batch’s ByteBuffer is prematurely deallocated and returned to the buffer pool. If a subsequent producer batch—potentially destined for a different topic—reuses this freed buffer before the original network request completes, the buffer contents may become corrupted. This can result in messages being delivered to unintended topics without any error being reported to the producer. Data Confidentiality: Messages intended for one topic may be delivered to a different topic, potentially exposing sensitive data to consumers who have access to the destination topic but not the intended source topic. Data Integrity: Consumers on the receiving topic may encounter unexpected or incompatible messages, leading to deserialization failures, processing errors, and corrupted downstream data. This issue affects Apache Kafka versions ≤ 3.9.1, ≤ 4.0.1, and  ≤ 4.1.1. Kafka users are advised to upgrade to 3.9.2, 4.0.2, 4.1.2, 4.2.0, or later to address this vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-362CWE-416

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • kafka

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 2 mentions (2026-04-08); latest day: 1
  • 5 total mentions across 4 days

Affected systems

Vendors
Products
kafka

Deep dive

Activity timeline5 mentions / 4d
01122Mentions · 2026-04-07: 1Mentions · 2026-04-08: 2Mentions · 2026-04-20: 1Mentions · 2026-07-22: 1Patch / Workaround · 2026-04-20: 1Patch / Workaround · 2026-07-22: 1Technical Details · 2026-04-07: 1Technical Details · 2026-04-08: 2Technical Details · 2026-04-20: 104-0704-0804-2007-22
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-071
Disclosure1
2026-04-082
Disclosure2
2026-04-201
Disclosure1
2026-07-221
Patch1
Full discourse5 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-35554: Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition https://www.openwall.com/lists/oss-security/2026/04/07/6

    Post summary

    The text announces a new race‑condition vulnerability (CVE‑2026‑35554) in Apache Kafka Clients that can lead to message corruption and misrouting.

    11071658
    4.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-35554 A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce ba… https://www.cve.org/CVERecord?id=CVE-2026-35554

    Post summary

    The post announces CVE‑2026‑35554 as a race condition in Kafka’s Java producer, detailing how it can silently misroute messages to wrong topics, with no evidence of exploitation or patching information provided.

    000311.1K
    57.6K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-35554 A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics. When a produce ba… https://www.cve.org/CVERecord?id=CVE-2026-35554 ----- Traducción: CVE-2026-35554 Una… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑35554, detailing a race condition in Apache Kafka’s Java producer client that may lead to messages being silently delivered to wrong topics.

    0001050
    67 followersView on X
  • Meridian Group@MeridianEU
    Patch

    HPE patches CVE-2025-69419 and CVE-2026-35554 in Telco Automated Assurance software v1.4 and earlier. Advisory co-issued with Canadian Centre for Cyber Security. No active exploitation reported; patching recommended. https://t.co/pGtbeGuIMK

    Post summary

    HPE releases patches for CVE‑2025‑69419 and CVE‑2026‑35554 in Telco Automated Assurance software, with an advisory issued alongside the Canadian Centre for Cyber Security; no active exploitation reported and patching is advised.

    0000044
    67 followersView on X
  • HeroDevs@herodevs
    Disclosure

    🚨 New CVE Alert: CVE-2026-35554 (Apache Kafka) A race condition in the Kafka producer client can cause messages to be silently delivered to the wrong topic — no errors, no alerts, just corrupted or misrouted data. Why it matters: ❌ Data confidentiality risk — sensitive data may leak across topics ❌ Data integrity risk — downstream systems process unexpected payloads ❌ Silent failures are harder to detect than loud ones Affected versions: kafka-clients 2.8.0–3.9.1, 4.0.0–4.0.1, and 4.1.0–4.1.1. Fixes are available in 3.9.2, 4.0.2, 4.1.2, and 4.2.0+ — but teams on 3.8.x and older have no in-branch patch and will need to upgrade branches. 🔗 https://www.herodevs.com/blog-posts/cve-2026-35554-apache-kafka-producer-message-corruption-and-silent-misrouting-buffer-pool-race-condition?utm_source=x-twitter&utm_medium=organic-social&utm_campaign=2026q2_cra-article-14_global #Kafka #CVE #DataIntegrity #AppSec #OpenSourceSecurity #DevSecOps #HeroDevs

    Post summary

    A new race‑condition vulnerability (CVE‑2026‑35554) in Apache Kafka producers silently misroutes messages across topics; patches are available for affected releases, and older versions require upgrading.

    00000161
    2.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachekafka---

Explore more