LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →
Home / Vulnerability Intelligence / CVE-2026-35554

CVE-2026-35554 - Vulnerability Analysis

HighCVSS: 8.7

Last Updated: April 7, 2026

Apache Kafka - Race Condition

Published: April 7, 2026Updated: April 7, 2026Remote Exploitable

Overview

Apache Kafka ≤ 3.9.1, ≤ 4.0.1, and ≤ 4.1.1 contain a race condition in the Java producer client's buffer pool management, causing messages to be silently delivered to incorrect topics, letting attackers cause data confidentiality and integrity issues, exploit requires message batch expiration during network request.

Severity & Score

Severity: High
CVSS Score: 8.7

Impact

Messages can be delivered to wrong topics, exposing sensitive data and causing data corruption or processing errors.

Mitigation

Upgrade to versions 3.9.2, 4.0.2, 4.1.2, 4.2.0 or later.

Details

CVE ID
CVE-2026-35554
Severity
High
CVSS Score
8.7
Type
race_condition
Status
new

CWE

  • CWE-362

CVSS Metrics

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N