UBUNTU-CVE-2026-33558

Source
https://ubuntu.com/security/CVE-2026-33558
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-33558.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2026-33558
Upstream
  • CVE-2026-33558
Published
2026-04-20T14:16:00Z
Modified
2026-05-14T14:39:57.475188Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

Information exposure vulnerability has been identified in Apache Kafka. The NetworkClient component will output entire requests and responses information in the DEBUG log level in the logs. By default, the log level is set to INFO level. If the DEBUG level is enabled, the sensitive information will be exposed via the requests and responses output log. The entire lists of impacted requests and responses are: * AlterConfigsRequest * AlterUserScramCredentialsRequest * ExpireDelegationTokenRequest * IncrementalAlterConfigsRequest * RenewDelegationTokenRequest * SaslAuthenticateRequest * createDelegationTokenResponse * describeDelegationTokenResponse * SaslAuthenticateResponse This issue affects Apache Kafka: from any version supported the listed API above through v3.9.1, v4.0.0. We advise the Kafka users to upgrade to v3.9.2, v4.0.1, or later to avoid this vulnerability.

References

Affected packages

Ubuntu:Pro:18.04:LTS / kafka

Package

Name
kafka
Purl
pkg:deb/ubuntu/kafka@2.2.2u1-0ubuntu1+esm2?arch=source&distro=esm-apps/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.2.0u2-0ubuntu3.1
2.2.0u2-0ubuntu3.2
2.2.2u1-0ubuntu1+esm2

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.2.2u1-0ubuntu1+esm2",
            "binary_name": "kafka"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-33558.json"