Redpanda is a Kafka-compatible streaming and event-processing platform deployed in data infrastructure environments, and the vulnerability footprint observed for the product centers on input validation, credential protection, and authorization mechanisms. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Redpanda over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50976CRITICAL Redpanda before 23.1.21 and 23.2.x before 23.2.18 has missing authorization checks in the Transactions API. | Dec 18, 2023 | 9.8 | 24 | NO | NO |
CVE-2023-24619MEDIUM Redpanda before 22.3.12 discloses cleartext AWS credentials. The import functionality in the rpk binary logs an AWS Access Key ID and Secret in cleartext to standard output, allowi | Feb 13, 2023 | 5.5 | 19 | NO | NO |
CVE-2023-30450MEDIUM rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically | Apr 8, 2023 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Redpanda.
Media articles that mention a CVE ID that affects a product developed by Redpanda — matched by CVE ID, not by vendor name.