DEBIAN-CVE-2026-10143

Source
https://security-tracker.debian.org/tracker/CVE-2026-10143
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-10143.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-10143
Upstream
  • CVE-2026-10143
Published
2026-06-10T22:16:55.503Z
Modified
2026-06-11T09:03:53.977980062Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the client event loop by supplying an excessively large iteration count. In scram.py, ScramClient.processserverfirstmessage() passes the broker-controlled SCRAM iteration count directly to hashlib.pbkdf2hmac() without validation, blocking producer sends, consumer polls, admin operations, and heartbeats, which can cause consumer group eviction and repeated reconnect failures.

References

Affected packages

Debian:11 / python-kafka

Package

Name
python-kafka
Purl
pkg:deb/debian/python-kafka?arch=source&distro=bullseye

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.1-2
2.0.2-1
2.0.2-2
2.0.2-3
2.0.2-4
2.0.2-5
2.0.2-6
2.0.2-7
2.0.2-8
2.0.2-9
2.0.2-10
2.0.2-11

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-10143.json"

Debian:12 / python-kafka

Package

Name
python-kafka
Purl
pkg:deb/debian/python-kafka?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.2-3
2.0.2-4
2.0.2-5
2.0.2-6
2.0.2-7
2.0.2-8
2.0.2-9
2.0.2-10
2.0.2-11

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-10143.json"

Debian:13 / python-kafka

Package

Name
python-kafka
Purl
pkg:deb/debian/python-kafka?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.2-9
2.0.2-10
2.0.2-11

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-10143.json"

Debian:14 / python-kafka

Package

Name
python-kafka
Purl
pkg:deb/debian/python-kafka?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.0.2-9
2.0.2-10
2.0.2-11

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-10143.json"