strimzi-kafka-operator

Direct Vulnerabilities

Known vulnerabilities in the strimzi-kafka-operator package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
Improper Verification of Cryptographic Signature

<1.2.0-r4
  • L
CVE-2026-40984

<1.2.0-r4
  • L
GHSA-3pjw-73gf-8qr5

<1.2.0-r4
  • L
GHSA-c653-97m9-rcg9

<1.2.0-r4
  • L
GHSA-g3pr-3p32-fp23

<1.2.0-r4
  • L
GHSA-93wv-jw9v-4972

<1.2.0-r4
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<1.2.0-r4
  • L
GHSA-mhm7-754m-9p8w

<1.2.0-r4
  • L
Resource Exhaustion

<1.2.0-r4
  • L
Improper Check for Unusual or Exceptional Conditions

<1.2.0-r5
  • L
GHSA-c4c3-7fpv-j4q5

<1.2.0-r5
  • L
Algorithmic Complexity

<1.2.0-r5
  • L
GHSA-fccg-mwvh-qqg4

<1.2.0-r5
  • L
CVE-2026-18401

<1.2.0-r5
  • L
GHSA-6qm2-mcq7-53qp

<1.2.0-r5
  • L
Information Exposure Through Caching

<1.2.0-r5
  • L
GHSA-8c42-7qj2-3j46

<1.2.0-r5
  • L
Improper Encoding or Escaping of Output

<1.2.0-r5
  • L
GHSA-qv9r-c865-cp47

<1.2.0-r5
  • L
Missing Release of Resource after Effective Lifetime

<1.2.0-r5
  • H
HTTP Request Smuggling

<1.2.0-r5
  • H
Loop with Unreachable Exit Condition ('Infinite Loop')

<1.2.0-r5
  • L
Improper Access Control

<1.2.0-r5
  • L
GHSA-7p3p-8qv8-m2vh

<1.2.0-r4
  • L
GHSA-6cqp-g7gg-8hr5

<1.2.0-r5
  • L
Information Exposure

<1.2.0-r5
  • L
GHSA-4mp9-239f-g9hg

<1.2.0-r5
  • L
Use of Non-Canonical URL Paths for Authorization Decisions

<1.2.0-r5
  • L
GHSA-5gvw-p9qm-jgwh

<1.2.0-r5
  • L
GHSA-558v-64gr-wgg4

<1.2.0-r5
  • L
GHSA-f4v5-65jj-pcr2

<1.2.0-r5
  • H
Resource Exhaustion

<1.2.0-r5
  • L
GHSA-mfg7-5gfp-c4w3

<1.2.0-r5
  • M
CRLF Injection

<1.2.0-r5
  • L
GHSA-6jqx-86gh-f27w

<1.2.0-r5
  • L
GHSA-c69g-56f8-xwqj

<1.2.0-r5
  • L
GHSA-w7x5-g22v-xqhr

<1.2.0-r5
  • M
HTTP Request Smuggling

<1.2.0-r5
  • L
Resource Exhaustion

<1.2.0-r5
  • L
GHSA-xx22-p4ch-683r

<1.2.0-r5
  • L
GHSA-q4f6-jm68-57ww

<1.2.0-r5
  • L
Incorrect Authorization

<1.2.0-r5
  • L
GHSA-r7wm-3cxj-wff9

<1.2.0-r5
  • L
GHSA-gcjf-9mgh-3p7g

<1.2.0-r5
  • L
NULL Pointer Dereference

<1.2.0-r5
  • L
GHSA-mvh2-crg5-v77c

<1.2.0-r5
  • L
GHSA-jppx-w49h-x2qq

<1.2.0-r5
  • L
Improper Input Validation

<1.2.0-r4
  • H
Allocation of Resources Without Limits or Throttling

<1.2.0-r5
  • L
Resource Exhaustion

<1.2.0-r5
  • L
Resource Exhaustion

<1.2.0-r5
  • L
GHSA-hpcc-26xq-25fv

<1.2.0-r5
  • L
GHSA-3g76-f9xq-8vp6

<1.2.0-r5
  • M
Allocation of Resources Without Limits or Throttling

<1.2.0-r5
  • L
Information Exposure

<1.2.0-r5
  • L
GHSA-w573-9ffj-6ff9

<1.2.0-r5
  • L
GHSA-5jmj-h7xm-6q6v

<1.2.0-r4
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<1.2.0-r4
  • L
Incorrect Authorization

<1.2.0-r5
  • L
Improperly Controlled Modification of Dynamically-Determined Object Attributes

<1.2.0-r5
  • M
Allocation of Resources Without Limits or Throttling

<1.2.0-r5
  • L
GHSA-563q-j3cm-6jxm

<1.2.0-r5
  • H
Resource Exhaustion

<1.2.0-r5
  • L
GHSA-5x3r-wrvg-rp6q

<1.2.0-r5
  • L
GHSA-hgj6-7826-r7m5

<1.2.0-r5
  • L
GHSA-hvcg-qmg6-jm4c

<1.2.0-r5
  • L
Incorrect Authorization

<1.2.0-r5
  • L
GHSA-c2gf-v879-257j

<1.2.0-r5
  • L
GHSA-j3rv-43j4-c7qm

<1.2.0-r5
  • L
GHSA-rcqc-6cw3-h962

<1.2.0-r5
  • L
HTTP Request Smuggling

<1.2.0-r5
  • L
Incomplete Blacklist

<1.2.0-r5
  • L
Resource Exhaustion

<1.2.0-r5
  • L
GHSA-rmj7-2vxq-3g9f

<1.2.0-r5
  • L
GHSA-9fxm-vc8v-hj55

<1.2.0-r5
  • L
Incomplete Blacklist

<1.2.0-r5
  • L
GHSA-5hh8-q8hv-fr38

<1.2.0-r5
  • L
Server-Side Request Forgery (SSRF)

<1.2.0-r5
  • C
HTTP Request Smuggling

<1.0.0-r8
  • L
GHSA-355h-qmc2-wpwf

<1.0.0-r8
  • L
GHSA-676x-f7gg-47vc

<1.2.0-r5
  • L
GHSA-xmv7-r254-6q78

<1.2.0-r5
  • L
GHSA-5pvg-856g-cp85

<1.2.0-r5
  • C
Insufficient Verification of Data Authenticity

<1.2.0-r5
  • C
Insufficient Verification of Data Authenticity

<1.2.0-r5
  • L
Use of Insufficiently Random Values

<1.2.0-r5
  • L
GHSA-3qp7-7mw8-wx86

<1.2.0-r5
  • L
Improper Access Control

<1.2.0-r5
  • L
Allocation of Resources Without Limits or Throttling

<1.2.0-r5
  • L
GHSA-x4gw-5cx5-pgmh

<1.2.0-r5
  • L
GHSA-mj4r-2hfc-f8p6

<1.2.0-r5
  • H
HTTP Response Splitting

<1.2.0-r5
  • L
GHSA-45q3-82m4-75jr

<1.2.0-r5
  • L
Resource Exhaustion

<1.2.0-r5
  • L
Missing Release of Resource after Effective Lifetime

<1.2.0-r5
  • L
Resource Exhaustion

<1.2.0-r5
  • L
GHSA-f6hv-jmp6-3vwv

<1.2.0-r5
  • L
GHSA-cm33-6792-r9fm

<1.2.0-r5
  • L
GHSA-rwm7-x88c-3g2p

<1.2.0-r5
  • C
Improper Input Validation

<1.2.0-r5
  • C
HTTP Request Smuggling

<1.2.0-r5
  • L
GHSA-57rv-r2g8-2cj3

<1.2.0-r5
  • L
GHSA-v8h7-rr48-vmmv

<1.2.0-r5
  • L
GHSA-38f8-5428-x5cv

<1.2.0-r5
  • L
GHSA-m4cv-j2px-7723

<1.2.0-r5
  • L
Integer Overflow or Wraparound

<1.2.0-r5
  • L
GHSA-xxqh-mfjm-7mv9

<1.2.0-r5
  • L
CRLF Injection

<1.2.0-r5
  • C
HTTP Request Smuggling

<1.2.0-r5
  • H
HTTP Request Smuggling

<1.2.0-r5
  • L
GHSA-wf66-mphr-4c4r

<1.2.0-r5
  • L
Information Exposure Through Server Log Files

<1.2.0-r5
  • L
GHSA-5qcv-4rpc-jp93

<1.2.0-r5
  • L
Race Condition

<1.2.0-r5
  • H
Improper Encoding or Escaping of Output

<1.2.0-r5
  • L
GHSA-445c-vh5m-36rj

<1.2.0-r5
  • H
Improper Encoding or Escaping of Output

<1.2.0-r5
  • H
Improper Output Neutralization for Logs

<1.2.0-r5
  • L
GHSA-w35j-pv5h-q9q9

<1.2.0-r5
  • L
GHSA-6hg6-v5c8-fphq

<1.2.0-r5
  • L
GHSA-3pxv-7cmr-fjr4

<1.2.0-r5
  • M
Improper Validation of Certificate with Host Mismatch

<1.2.0-r5
  • H
Allocation of Resources Without Limits or Throttling

<1.2.0-r5
  • L
GHSA-w9fj-cfpg-grvv

<1.2.0-r5
  • L
CRLF Injection

<1.2.0-r5
  • L
GHSA-pwqr-wmgm-9rr8

<1.2.0-r5
  • L
GHSA-wjpw-4j6x-6rwh

<1.2.0-r5
  • M
Improper Input Validation

<1.2.0-r5
  • L
HTTP Request Smuggling

<1.2.0-r5
  • L
GHSA-84h7-rjj3-6jx4

<1.2.0-r5
  • L
CVE-2025-12183

<1.2.0-r5
  • L
GHSA-cmp6-m4wj-q63q

<1.2.0-r5
  • L
Information Exposure

<1.2.0-r5
  • L
GHSA-vqf4-7m7x-wgfc

<1.2.0-r5
  • L
GHSA-crhr-qqj8-rpxc

<1.2.0-r5
  • H
Information Exposure Through Log Files

<1.2.0-r5
  • L
GHSA-7xrh-hqfc-g7qr

<1.2.0-r5
  • H
Improper Certificate Validation

<1.2.0-r5
  • L
GHSA-72hv-8253-57qq

<1.2.0-r5
  • L
GHSA-xxh7-fcf3-rj7f

<1.2.0-r5
  • L
Resource Exhaustion

<1.2.0-r5
  • L
GHSA-cphf-4846-3xx9

<0.50.0-r0
  • M
HTTP Request Smuggling

<0.50.0-r0
  • L
GHSA-vc5p-v9hr-52mj

<0.49.1-r2
  • M
Improper Certificate Validation

<0.49.1-r2
  • L
CVE-2024-29371

<0.49.1-r5
  • L
GHSA-3677-xxcr-wjqv

<0.49.1-r5
  • H
Files or Directories Accessible to External Parties

<0.48.0-r1
  • M
Cross-site Scripting (XSS)

<0.48.0-r1
  • L
Improper Handling of Insufficient Permissions or Privileges

<0.47.0-r8
  • L
GHSA-2hmj-97jw-28jh

<0.47.0-r8
  • L
GHSA-3p8m-j85q-pgmj

<0.47.0-r7
  • L
GHSA-fghv-69vj-qj49

<0.47.0-r7
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<0.47.0-r7
  • H
HTTP Request Smuggling

<0.47.0-r7
  • H
Allocation of Resources Without Limits or Throttling

<0.47.0-r3
  • L
GHSA-prj3-ccx8-p6x4

<0.47.0-r3
  • L
GHSA-p7c9-8xx8-h74f

<0.46.1-r0
  • L
CVE-2024-56128

<0.46.1-r0
  • L
CVE-2025-27817

<0.46.0-r6
  • L
CVE-2025-48734

<0.46.0-r5
  • L
Resource Exhaustion

<0.45.0-r2
  • M
Allocation of Resources Without Limits or Throttling

<0.45.0-r1
  • L
CVE-2025-24970

<0.47.0-r1
  • L
Improper Privilege Management

<0.44.0-r2