Openshift-Serverless-1 Kn-Ekb-Dispatcher-Rhel9 vulnerabilities
2 known vulnerabilities affecting openshift-serverless-1/kn-ekb-dispatcher-rhel9.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1
Vulnerabilities
Page 1 of 1
CVE-2026-33557CRITICALCVSS 9.12026-04-20
CVE-2026-33557 [CRITICAL] CWE-303 kafka: Apache Kafka: Authentication bypass via improper JWT validation
kafka: Apache Kafka: Authentication bypass via improper JWT validation
A flaw was found in Apache Kafka. By default, the `sasl.oauthbearer.jwt.validator.class` property is set to `org.apache.kafka.common.security.oauthbearer.DefaultJwtValidator`, which does not validate JSON Web Token (JWT) signatures, issuers, or audiences. A remote attacker can exploit this by crafting a malicious JWT toke
redhat
CVE-2026-35554HIGHCVSS 8.72026-04-07
CVE-2026-35554 [HIGH] CWE-367 Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management
Apache Kafka Clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management
A flaw was found in the Apache Kafka Java producer client. A race condition in the client's buffer pool management can cause messages to be silently delivered to incorrect topics. This occurs
redhat