CVE-2026-25999

Source
https://cve.org/CVERecord?id=CVE-2026-25999
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25999.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-25999
Aliases
  • GHSA-rp26-qv9w-xr5q
Published
2026-02-11T21:00:30Z
Modified
2026-08-12T15:31:58Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H CVSS Calculator
Summary
Klaw has an improper authorisation check on /resetMemoryCache
Details

Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper access control vulnerability that allows unauthorized users to trigger a reset or deletion of metadata for any tenant. By sending a crafted request to the /resetMemoryCache endpoint, an attacker can clear cached configurations, environments, and cluster data. This vulnerability is fixed in 2.10.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-285"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25999.json"
}
References

Affected packages

Git / github.com/aiven-open/klaw

Affected ranges

Type
GIT
Repo
https://github.com/aiven-open/klaw
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "cpe": "cpe:2.3:a:aiven:klaw:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.10.2"
        }
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.0.0
v.*
v.2.6.0
v1.*
v1.1.0
v1.2.0
v2.*
v2.0.0
v2.1.0
v2.10.0
v2.10.1
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.7.0
v2.8.0
v2.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25999.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "306360994372993250348508872170603247308",
                "272188010370807196142997922820141825303",
                "8541717271924304080719792911515623369",
                "233958640032537030238062040257025281593",
                "324498631389457694903772077729344280567",
                "33617773262469598814372893584857514478",
                "152297790026614686388399696849563657784",
                "88313166850082545840729972993415078359",
                "285525038857477499674909472925064053925",
                "159230446039195506135015615447488495440",
                "100841535560209611189351669304871390073",
                "289855470334530897388674086337131010693",
                "181913182998811399471617383786720088589",
                "7720319946903789588633356756329017420",
                "324498631389457694903772077729344280567",
                "33617773262469598814372893584857514478",
                "90914288935725456525390391587865863637",
                "217265189017568161780257573643218667214",
                "45886001985857312237473451175070277315"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-25999-07e9121e",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/test/java/io/aiven/klaw/service/UtilControllerServiceTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "44734951941540807426043680462618471994",
            "length": 785
        },
        "id": "CVE-2026-25999-103a4549",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/main/java/io/aiven/klaw/config/ConfigUtils.java",
            "function": "applyHttpSecurityConfig"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "313834179744190395871066788150399690085",
            "length": 153
        },
        "id": "CVE-2026-25999-1775b5e9",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/main/java/io/aiven/klaw/controller/UtilController.java",
            "function": "resetMemoryCache"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "214032340629346672530865034647164446677",
            "length": 489
        },
        "id": "CVE-2026-25999-215a6e43",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/test/java/io/aiven/klaw/service/UtilControllerServiceTest.java",
            "function": "resetCacheNotAuthorized"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "156026122269467503163070331386697968187",
                "309264451252014547816192856011183838891",
                "253064676035050233502481827058723296850",
                "93877037460188463246620709211379517946"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-25999-312d5472",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/main/java/io/aiven/klaw/config/ConfigUtils.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "24806314133742703021338972960783144467",
            "length": 729
        },
        "id": "CVE-2026-25999-3efa305d",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/main/java/io/aiven/klaw/config/SecurityConfigNoSSO.java",
            "function": "securityFilterChain"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "53111505576804944119101155227571494044",
            "length": 1172
        },
        "id": "CVE-2026-25999-9aa8a2ae",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/main/java/io/aiven/klaw/service/CommonUtilsService.java",
            "function": "resetCacheOnOtherServers"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "81646998477010980065201713771676341268",
                "274835296542859760672098211872654301077",
                "146602497720127959898095754172648200157",
                "308513204831544866027462239433130106953"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-25999-a1af9d24",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/test/java/io/aiven/klaw/controller/UtilControllerTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "236788014738034644361663338913053291793",
            "length": 494
        },
        "id": "CVE-2026-25999-a643d015",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/test/java/io/aiven/klaw/service/UtilControllerServiceTest.java",
            "function": "resetCache"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "8846973360033805104168374443171843367",
                "150886369171488159095828364504009662508",
                "79768399169145896163023104680110404699",
                "10308205867892243475088511067146382695",
                "183614578332110173882044695881927027200",
                "222400066869717482109860611654544895107",
                "306754607248161284828894675872003300387",
                "293093664154561992078625558302813022687",
                "290743621553371954505824600234057542120",
                "260632946064575964000112816163498421755",
                "14323386008413301357675620395388627311",
                "330872959141000422353897486204357076556",
                "189418979708453670273797564419113964304",
                "115430052770519857387797495003999597263",
                "334160917734341215241841557382923977650"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-25999-abf0f422",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/main/java/io/aiven/klaw/service/UtilControllerService.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "253006144826224051806916233302593443267",
            "length": 578
        },
        "id": "CVE-2026-25999-b2634f0e",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/test/java/io/aiven/klaw/controller/UtilControllerTest.java",
            "function": "resetMemoryCache"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "172764066385864110329207165123921632855",
                "283047025814250871328651879289866235508",
                "118993911031398220284839641039900453933",
                "124378780084258849121530106918359121687",
                "141488861446761744045181569738661580424"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-25999-ba8e436b",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/main/java/io/aiven/klaw/controller/UtilController.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "256356884060256588572479991904544443946",
                "309264451252014547816192856011183838891",
                "253064676035050233502481827058723296850",
                "93877037460188463246620709211379517946"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-25999-d9c520d3",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/main/java/io/aiven/klaw/config/SecurityConfigNoSSO.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "149043346349386900350596171146926898344",
                "305196801733851080171159703035568650657",
                "291534471190434544062245874435619326526",
                "235949530631845871284923785043328329931",
                "12380007417898230167988394222700105481",
                "280035799344897145618786560612887697319",
                "30906907383647841107098686640983733612",
                "188791098435045362714792953725126828593",
                "61635538685353906829264813379471894262",
                "183715301753375707755859985423065446629",
                "271017760794813228801352012253533522108",
                "3223044092683766641471921419030812749",
                "328059891077179253171240288906584838346",
                "224825255235788066277371365723186643133",
                "225069206786098658300259559941888185010",
                "12518487481621241087442389340482640433",
                "268719877561396383709800055850613839037",
                "150816921098026913299392422367166946458",
                "136091316497007154848271275781826386977",
                "198780663636917681950560501784817671463",
                "306217201210717995520845973416476150075",
                "316688794651432597889378722832050110843",
                "183770182732360835127818722381800422506",
                "19187863245970342284614982175243545747"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-25999-ec906b8e",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/main/java/io/aiven/klaw/service/CommonUtilsService.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "237569681829982812714397495743267487972",
            "length": 963
        },
        "id": "CVE-2026-25999-ef677929",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
        "target": {
            "file": "core/src/main/java/io/aiven/klaw/service/UtilControllerService.java",
            "function": "resetCache"
        }
    }
]
vanir_signatures_modified
"2026-08-12T15:31:58Z"