Improper Validation of Specified Index, Position, or Offset in Input Affecting org.apache.kafka:kafka-clients package, versions [4.1.0,4.1.2)


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.2% (42nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGAPACHEKAFKA-16207346
  • published24 Apr 2026
  • disclosed20 Apr 2026
  • creditPavel Romanov

Introduced: 20 Apr 2026

NewCVE-2026-33557  (opens in a new tab)
CWE-1285  (opens in a new tab)

How to fix?

Upgrade org.apache.kafka:kafka-clients to version 4.1.2 or higher.

Overview

org.apache.kafka:kafka-clients is a streaming platform that can publish and subscribe to streams of records, store streams of records in a fault-tolerant durable way, and process streams of records as they occur.

Affected versions of this package are vulnerable to Improper Validation of Specified Index, Position, or Offset in Input in the DefaultJwtValidator oauthbearer validator when sasl.enabled.mechanisms=OAUTHBEARER is configured on the server side. An attacker can gain unauthorized access by supplying a crafted JWT token with arbitrary issuer and user information.

CVSS Base Scores

version 4.0
version 3.1