CVE-2026-33558 Details
Description
Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the sensitive information will be exposed via the requests and responses output log. The entire lists of impacted requests and responses are: * AlterConfigsRequest * AlterUserScramCredentialsRequest * ExpireDelegationTokenRequest * IncrementalAlterConfigsRequest * RenewDelegationTokenRequest * SaslAuthenticateRequest * createDelegationTokenResponse * describeDelegationTokenResponse * SaslAuthenticateResponse This issue affects Apache Kafka: from any version supported the listed API above through v3.9.1, v4.0.0. We advise the Kafka users to upgrade to v3.9.2, v4.0.1, or later to avoid this vulnerability.
A vulnerability allowing information exposure has been identified in Apache Kafka and its clients. The issue arises in the NetworkClient component, which logs complete request and response details at the DEBUG log level. By default, this log level is set to INFO. However, if DEBUG is enabled, sensitive information can be leaked through the logged requests and responses. The vulnerability affects Apache Kafka versions 0.11.0 through 3.9.1, as well as 4.0.0, and Apache Kafka Clients (org.apache.kafka:kafka-clients) versions 0.11.0 through 3.9.1 and 4.0.0.
Users are advised to upgrade to Apache Kafka versions 3.9.2, 4.0.1, or 4.1.0 and later. For those using Apache Kafka Connect, it is recommended to validate connector configurations and only allow trusted JNDI configurations.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 20, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/04/17/3 | CVE | Mailing List |
| https://kafka.apache.org/cve-list | [email protected] | Vendor Advisory |
| https://lists.apache.org/thread/pz5g4ky3h0k91tfd14p0dzqjp80960kl | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-533 | DEPRECATED: Information Exposure Through Server Log Files | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache kafka | >= 0.11.0.0, < 3.9.2 4.0.0 - 4.0.0 rc0 4.0.0 rc1 4.0.0 rc3 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | Initial Analysis | [email protected] |
| Apr 20, 2026 | CVE Modified | CISA-ADP |
| Apr 20, 2026 | New CVE Received | [email protected] |
| Apr 20, 2026 | CVE Modified | CVE |