Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to 2.10.2, there is an improper access control vulnerability that allows unauthorized users to trigger a reset or deletion of metadata for any tenant. By sending a crafted request to the /resetMemoryCache endpoint, an attacker can clear cached configurations, environments, and cluster data. This vulnerability is fixed in 2.10.2.
{
"cna_assigner": "GitHub_M",
"cwe_ids": [
"CWE-285"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/25xxx/CVE-2026-25999.json"
}{
"cpe": "cpe:2.3:a:aiven:klaw:*:*:*:*:*:*:*:*",
"extracted_events": [
{
"introduced": "0"
},
{
"fixed": "2.10.2"
}
],
"source": [
"CPE_RANGE",
"REFERENCES"
]
}
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-25999.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"306360994372993250348508872170603247308",
"272188010370807196142997922820141825303",
"8541717271924304080719792911515623369",
"233958640032537030238062040257025281593",
"324498631389457694903772077729344280567",
"33617773262469598814372893584857514478",
"152297790026614686388399696849563657784",
"88313166850082545840729972993415078359",
"285525038857477499674909472925064053925",
"159230446039195506135015615447488495440",
"100841535560209611189351669304871390073",
"289855470334530897388674086337131010693",
"181913182998811399471617383786720088589",
"7720319946903789588633356756329017420",
"324498631389457694903772077729344280567",
"33617773262469598814372893584857514478",
"90914288935725456525390391587865863637",
"217265189017568161780257573643218667214",
"45886001985857312237473451175070277315"
],
"threshold": 0.9
},
"id": "CVE-2026-25999-07e9121e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/test/java/io/aiven/klaw/service/UtilControllerServiceTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "44734951941540807426043680462618471994",
"length": 785
},
"id": "CVE-2026-25999-103a4549",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/main/java/io/aiven/klaw/config/ConfigUtils.java",
"function": "applyHttpSecurityConfig"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "313834179744190395871066788150399690085",
"length": 153
},
"id": "CVE-2026-25999-1775b5e9",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/main/java/io/aiven/klaw/controller/UtilController.java",
"function": "resetMemoryCache"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "214032340629346672530865034647164446677",
"length": 489
},
"id": "CVE-2026-25999-215a6e43",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/test/java/io/aiven/klaw/service/UtilControllerServiceTest.java",
"function": "resetCacheNotAuthorized"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"156026122269467503163070331386697968187",
"309264451252014547816192856011183838891",
"253064676035050233502481827058723296850",
"93877037460188463246620709211379517946"
],
"threshold": 0.9
},
"id": "CVE-2026-25999-312d5472",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/main/java/io/aiven/klaw/config/ConfigUtils.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "24806314133742703021338972960783144467",
"length": 729
},
"id": "CVE-2026-25999-3efa305d",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/main/java/io/aiven/klaw/config/SecurityConfigNoSSO.java",
"function": "securityFilterChain"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "53111505576804944119101155227571494044",
"length": 1172
},
"id": "CVE-2026-25999-9aa8a2ae",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/main/java/io/aiven/klaw/service/CommonUtilsService.java",
"function": "resetCacheOnOtherServers"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"81646998477010980065201713771676341268",
"274835296542859760672098211872654301077",
"146602497720127959898095754172648200157",
"308513204831544866027462239433130106953"
],
"threshold": 0.9
},
"id": "CVE-2026-25999-a1af9d24",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/test/java/io/aiven/klaw/controller/UtilControllerTest.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "236788014738034644361663338913053291793",
"length": 494
},
"id": "CVE-2026-25999-a643d015",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/test/java/io/aiven/klaw/service/UtilControllerServiceTest.java",
"function": "resetCache"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"8846973360033805104168374443171843367",
"150886369171488159095828364504009662508",
"79768399169145896163023104680110404699",
"10308205867892243475088511067146382695",
"183614578332110173882044695881927027200",
"222400066869717482109860611654544895107",
"306754607248161284828894675872003300387",
"293093664154561992078625558302813022687",
"290743621553371954505824600234057542120",
"260632946064575964000112816163498421755",
"14323386008413301357675620395388627311",
"330872959141000422353897486204357076556",
"189418979708453670273797564419113964304",
"115430052770519857387797495003999597263",
"334160917734341215241841557382923977650"
],
"threshold": 0.9
},
"id": "CVE-2026-25999-abf0f422",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/main/java/io/aiven/klaw/service/UtilControllerService.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "253006144826224051806916233302593443267",
"length": 578
},
"id": "CVE-2026-25999-b2634f0e",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/test/java/io/aiven/klaw/controller/UtilControllerTest.java",
"function": "resetMemoryCache"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"172764066385864110329207165123921632855",
"283047025814250871328651879289866235508",
"118993911031398220284839641039900453933",
"124378780084258849121530106918359121687",
"141488861446761744045181569738661580424"
],
"threshold": 0.9
},
"id": "CVE-2026-25999-ba8e436b",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/main/java/io/aiven/klaw/controller/UtilController.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"256356884060256588572479991904544443946",
"309264451252014547816192856011183838891",
"253064676035050233502481827058723296850",
"93877037460188463246620709211379517946"
],
"threshold": 0.9
},
"id": "CVE-2026-25999-d9c520d3",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/main/java/io/aiven/klaw/config/SecurityConfigNoSSO.java"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"149043346349386900350596171146926898344",
"305196801733851080171159703035568650657",
"291534471190434544062245874435619326526",
"235949530631845871284923785043328329931",
"12380007417898230167988394222700105481",
"280035799344897145618786560612887697319",
"30906907383647841107098686640983733612",
"188791098435045362714792953725126828593",
"61635538685353906829264813379471894262",
"183715301753375707755859985423065446629",
"271017760794813228801352012253533522108",
"3223044092683766641471921419030812749",
"328059891077179253171240288906584838346",
"224825255235788066277371365723186643133",
"225069206786098658300259559941888185010",
"12518487481621241087442389340482640433",
"268719877561396383709800055850613839037",
"150816921098026913299392422367166946458",
"136091316497007154848271275781826386977",
"198780663636917681950560501784817671463",
"306217201210717995520845973416476150075",
"316688794651432597889378722832050110843",
"183770182732360835127818722381800422506",
"19187863245970342284614982175243545747"
],
"threshold": 0.9
},
"id": "CVE-2026-25999-ec906b8e",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/main/java/io/aiven/klaw/service/CommonUtilsService.java"
}
},
{
"deprecated": false,
"digest": {
"function_hash": "237569681829982812714397495743267487972",
"length": 963
},
"id": "CVE-2026-25999-ef677929",
"signature_type": "Function",
"signature_version": "v1",
"source": "https://github.com/aiven-open/klaw/commit/617ed96b1db111ed498d89132321bf39f486e3a1",
"target": {
"file": "core/src/main/java/io/aiven/klaw/service/UtilControllerService.java",
"function": "resetCache"
}
}
]
"2026-08-12T15:31:58Z"