strimzi-kafka-operator-topic-operator

Direct Vulnerabilities

Known vulnerabilities in the strimzi-kafka-operator-topic-operator package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • L
CVE-2026-40984

<1.1.0-r0
  • L
Improper Input Validation

<1.1.0-r0
  • L
Use of Non-Canonical URL Paths for Authorization Decisions

<1.1.0-r0
  • L
Improper Verification of Cryptographic Signature

<1.0.1-r2
  • M
Allocation of Resources Without Limits or Throttling

<1.0.1-r2
  • L
Improper Access Control

<1.0.1-r2
  • C
Insufficient Verification of Data Authenticity

<1.0.1-r2
  • L
Use of Insufficiently Random Values

<1.0.1-r2
  • L
Resource Exhaustion

<1.0.1-r2
  • L
Allocation of Resources Without Limits or Throttling

<1.0.1-r2
  • L
Information Exposure

<1.0.1-r2
  • L
HTTP Request Smuggling

<1.0.1-r2
  • H
Resource Exhaustion

<1.0.1-r2
  • C
Insufficient Verification of Data Authenticity

<1.0.1-r2
  • C
HTTP Request Smuggling

<1.0.1-r2
  • L
CVE-2025-12183

<0.51.0-r0
  • L
Information Exposure

<0.51.0-r0
  • L
Resource Exhaustion

<1.0.1-r1
  • C
HTTP Request Smuggling

<1.0.1-r1
  • C
Improper Input Validation

<1.0.1-r1
  • L
Integer Overflow or Wraparound

<1.0.1-r1
  • H
HTTP Request Smuggling

<1.0.1-r1
  • H
HTTP Response Splitting

<1.0.1-r1
  • L
Resource Exhaustion

<1.0.1-r1
  • C
HTTP Request Smuggling

<1.0.1-r1
  • L
CRLF Injection

<1.0.1-r1
  • M
Allocation of Resources Without Limits or Throttling

<1.0.0-r0
  • M
Improper Validation of Certificate with Host Mismatch

<1.0.0-r0
  • H
Improper Output Neutralization for Logs

<1.0.0-r0
  • H
Improper Encoding or Escaping of Output

<1.0.0-r0
  • H
Improper Encoding or Escaping of Output

<1.0.0-r0
  • L
Information Exposure Through Server Log Files

<0.48.0-r0
  • L
Improper Validation of Specified Index, Position, or Offset in Input

<0.51.0-r0
  • L
Race Condition

<0.51.0-r0
  • L
HTTP Request Smuggling

<0.51.0-r0
  • H
Allocation of Resources Without Limits or Throttling

<0.51.0-r0
  • L
GHSA-72hv-8253-57qq

<0.51.0-r1
  • M
Improper Input Validation

<0.51.0-r1
  • L
Resource Exhaustion

<0.51.0-r1
  • H
Improper Certificate Validation

<0.48.0-r0
  • H
Information Exposure Through Log Files

<0.48.0-r0
  • M
HTTP Request Smuggling

<0.48.0-r0
  • L
CRLF Injection

<0.50.0-r0
  • M
Improper Certificate Validation

<0.49.1-r2
  • L
Deserialization of Untrusted Data

<0.48.0-r0
  • L
CVE-2025-48734

<0.50.0-r0
  • L
Improper Handling of Insufficient Permissions or Privileges

<0.49.0-r0
  • L
CVE-2025-24970

<0.45.1-r3
  • L
CVE-2023-51775

<0.45.1-r3
  • L
Uncontrolled Recursion

<0.45.1-r3
  • L
CVE-2025-27817

<0.45.1-r3
  • L
CVE-2024-13009

<0.45.1-r3
  • M
Allocation of Resources Without Limits or Throttling

<0.45.1-r3
  • M
Cross-site Scripting (XSS)

<0.45.1-r3
  • L
Improper Privilege Management

<0.45.1-r3
  • L
Resource Exhaustion

<0.45.1-r3
  • L
Incorrect Authorization

<0.45.1-r3
  • L
CVE-2024-56128

<0.45.1-r3
  • H
CVE-2023-52428

<0.45.1-r3
  • H
Files or Directories Accessible to External Parties

<0.45.1-r3
  • M
Resource Exhaustion

<0.45.1-r3
  • L
Missing Authorization

<0.45.1-r3
  • M
CVE-2024-6763

<0.45.1-r1
  • L
Resource Exhaustion

<0.45.1-r1
  • H
HTTP Request Smuggling

<0.45.1-r1
  • H
Allocation of Resources Without Limits or Throttling

<0.45.1-r1
  • L
Uncontrolled Recursion

<0.45.1-r1
  • H
Improper Handling of Highly Compressed Data (Data Amplification)

<0.45.1-r1