CVE-2026-15911: Confluent Kafka Python Improper TLS Certificate Validation
Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
confluent-kafka (Python)to a version that resolves this vulnerability.Fixed in 2.15.0
Event History
Frequently Asked Questions
Which deployments are exposed by default?
Deployments using the Confluent Kafka Python client's HashiCorp Vault KMS integration are affected because TLS certificate verification is disabled by default for that integration.
What does an attacker need to exploit this issue?
The issue is remotely exploitable and does not require privileges or user interaction. Exploitation has high attack complexity.
What is the known impact?
A successful attack could allow a remote attacker to obtain sensitive information. No availability impact is indicated by the provided severity vector.