CVE-2026-35554 - Vulnerability Analysis
HighCVSS: 8.7Last Updated: April 7, 2026
Apache Kafka - Race Condition
Published: April 7, 2026Updated: April 7, 2026Remote Exploitable
Overview
Apache Kafka ≤ 3.9.1, ≤ 4.0.1, and ≤ 4.1.1 contain a race condition in the Java producer client's buffer pool management, causing messages to be silently delivered to incorrect topics, letting attackers cause data confidentiality and integrity issues, exploit requires message batch expiration during network request.
Severity & Score
Severity: High
CVSS Score: 8.7
Impact
Messages can be delivered to wrong topics, exposing sensitive data and causing data corruption or processing errors.
Mitigation
Upgrade to versions 3.9.2, 4.0.2, 4.1.2, 4.2.0 or later.
References
Related Resources
Details
- CVE ID
- CVE-2026-35554
- Severity
- High
- CVSS Score
- 8.7
- Type
- race_condition
- Status
- new
CWE
- CWE-362
CVSS Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N