Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-35554

30
FAUCET Score

OVERVIEW CVE-2026-35554 is a race condition vulnerability in Apache Kafka's Java producer client buffer pool management that causes messages to be silently delivered to incorrect topics. The flaw occurs when a produce batch expires while its network request remains in flight, causing premature buffer deallocation. Subsequent producer batches can reuse the freed buffer before the original request completes, resulting in corrupted message delivery to unintended topics. The vulnerability affects Kafka versions 3.9.1 and earlier, 4.0.1 and earlier, and 4.1.1 and earlier, requiring upgrades to versions 3.9.2, 4.0.2, 4.1.2, 4.2.0, or later. SEVERITY The vulnerability carries a CVSS 3.1 score of 8.7 (HIGH) with a network attack vector, high complexity, and no authentication requirement. The impact is significant across confidentiality and integrity dimensions: sensitive messages intended for one topic may be exposed to consumers of unintended topics, and recipients may encounter deserialization failures or corrupted downstream data. The remote exploitability combined with cross-scope impact elevates concern despite the relatively high attack complexity requirement. EXPLOITATION STATUS This vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities (KEV) catalog and shows no active exploitation indicators. The EPSS score of 0.000370 indicates extremely low exploitation probability relative to other CVEs, suggesting minimal real-world attacker interest at present. Community attention remains low, with no publicly available proof-of-concept code reported, allowing organizations a reasonable window for timely patching before widespread awareness increases exploitation likelihood.

Impacted Technologies

VendorProductVersion(s)CPE
Apache Software FoundationApache Kafka Clients
>= 2.8.0, <= 3.9.1, >= 4.0.0, <= 4.0.1, >= 4.1.0, <= 4.1.1CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

8.7HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
5.8
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.33%
Probability of exploitation in next 30 days
EPSS Percentile
25.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0033 is in the 5th percentile among its peer group of 8,918 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

mavenpatch availablevia ghsa
Product: org.apache.kafka:kafka-clientsFixed in: 3.9.2
mavenpatch availablevia ghsa
Product: org.apache.kafka:kafka-clientsFixed in: 4.0.2
mavenpatch availablevia ghsa
Product: org.apache.kafka:kafka-clientsFixed in: 4.1.2
apachevendor investigatingvia vendor_rss
View patch

Vendor Advisories (2)

mavenGHSA-5qcv-4rpc-jp93high

Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition

Apr 7, 2026
apacheapache:www.mail-archive.com/[email protected]/msg10874.html

CVE-2026-35554: Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition

Apr 7, 2026

References

openwall.com / lists/oss-security/2026/04/07/6
issues.apache.org / jira/browse/KAFKA-19012
lists.apache.org / thread/f07x7j8ovyqhjd1to25jsnqbm6wj01d6