7 Total advisories
7 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.apache.kafka:kafka-clients is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 5.3
CVE-2026-33558
Apache Kafka exposes sensitive information in its DEBUG logs
HIGH 8.7
CVE-2026-35554
Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
CRITICAL 9.1
CVE-2026-33557
Apache Kafka does not validate JWT tokens in its OAUTHBEARER authentication implementation
HIGH 7.5
CVE-2025-27817
Apache Kafka Client Arbitrary File Read and Server Side Request Forgery Vulnerability
MEDIUM 6.5
CVE-2024-31141
Apache Kafka Clients: Privilege escalation to filesystem read-access via automatic ConfigProvider
MEDIUM 5.9
CVE-2021-38153
Observable Discrepancy in Apache Kafka
MEDIUM 6.8
CVE-2017-12610
Improper Authentication in Apache Kafka
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes