GHSA-r427-j2h7-wv3m

Suggest an improvement
Source
https://github.com/advisories/GHSA-r427-j2h7-wv3m
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-r427-j2h7-wv3m/GHSA-r427-j2h7-wv3m.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-r427-j2h7-wv3m
Aliases
  • CVE-2026-55226
Published
2026-06-18T13:04:49Z
Modified
2026-06-18T13:16:06.467759007Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
Details

Impact

When only the Topic or only the User operators are deployed as part of the Entity Operator in the Kafka custom resource, the RBAC rights are not following the principle of least-privilege and the Entity Operator ServiceAccount still has access rights corresponding to both operators. That might allow the ServiceAccount to access KafkaUser custom resources and Secrets when the User operator is not deployed and access KafkaTopic custom resources when the Topic operator is not deployed.

Patches

The issue is fixed in Strimzi 1.0.1 and 1.1.0.

Workarounds

There is no workaround for this issue.

Database specific
{
    "nvd_published_at": null,
    "github_reviewed_at": "2026-06-18T13:04:49Z",
    "github_reviewed": true,
    "severity": "MODERATE",
    "cwe_ids": [
        "CWE-269",
        "CWE-272"
    ]
}
References

Affected packages

Maven / io.strimzi:strimzi

Package

Name
io.strimzi:strimzi
View open source insights on deps.dev
Purl
pkg:maven/io.strimzi/strimzi

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.0.1

Affected versions

0.*
0.9.0
0.10.0
0.11.0
0.11.1
0.11.2
0.11.3
0.11.4
0.12.0
0.12.1
0.12.2
0.13.0
0.14.0
0.15.0
0.16.0
0.16.1
0.16.2
0.17.0
0.18.0
0.19.0
0.20.0
0.20.1
0.21.0
0.21.1
0.22.0
0.22.1
0.23.0
0.24.0
0.25.0
0.26.0
0.26.1
0.27.0
0.27.1
0.28.0
0.29.0
0.30.0
0.31.0
0.31.1
0.32.0
0.33.0
0.33.1
0.33.2
0.34.0
0.35.0
0.35.1
0.36.0
0.36.1
0.37.0
0.38.0
0.39.0
0.40.0
0.41.0
0.42.0
0.43.0
0.44.0
0.45.0
0.45.1-RC1
0.45.1
0.45.2-RC1
0.45.2
0.46.0
0.46.1-RC1
0.46.1
0.47.0-RC1
0.47.0
0.48.0-RC1
0.48.0
0.49.0-RC1
0.49.0-RC2
0.49.0
0.49.1-RC1
0.49.1
0.50.0-RC1
0.50.0
0.50.1-RC1
0.50.1
0.51.0-RC1
0.51.0-RC2
0.51.0
1.*
1.0.0-RC1
1.0.0-RC2
1.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-r427-j2h7-wv3m/GHSA-r427-j2h7-wv3m.json"
last_known_affected_version_range
"<= 1.0.0"