logo

OAUTHBEARER Bypass and Sensitive Logging Leaks Hit Apache Kafka

ID: c14ef112-87ab-5e31-b509-b578483edfe9

STIX ID: report--c14ef112-87ab-5e31-b509-b578483edfe9

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-19

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed two Apache Kafka vulnerabilities: CVE-2026-33557 is an authentication bypass in DefaultJwtValidator that may accept unsigned or forged JWTs (affecting Kafka 4.1.0–4.1.1) and CVE-2026-33558 is a moderate-risk issue where DEBUG-level NetworkClient logging can leak full request/response contents (affecting a wide range of Kafka clients). The report provides affected/fixed versions and immediate mitigations—set sasl.oauthbearer.jwt.validator.class to BrokerJwtValidator or upgrade for CVE-2026-33557, and ensure NetworkClient log level is INFO or upgrade for CVE-2026-33558.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.