CVE-2026-35554: Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition

Published Apr 7, 2026
·
Updated

A race condition in the Apache Kafka Java producer client’s buffer pool management can cause messages to be silently delivered to incorrect topics.

When a produce batch expires due to delivery.timeout.ms while a network request containing that batch is still in flight, the batch’s ByteBuffer is prematurely deallocated and returned to the buffer pool. If a subsequent producer batch—potentially destined for a different topic—reuses this freed buffer before the original network request completes, the buffer contents may become corrupted. This can result in messages being delivered to unintended topics without any error being reported to the producer.

Data Confidentiality: Messages intended for one topic may be delivered to a different topic, potentially exposing sensitive data to consumers who have access to the destination topic but not the intended source topic.

Data Integrity: Consumers on the receiving topic may encounter unexpected or incompatible messages, leading to deserialization failures, processing errors, and corrupted downstream data.

This issue affects Apache Kafka versions ≤ 3.9.1, ≤ 4.0.1, and ≤ 4.1.1.

Kafka users are advised to upgrade to 3.9.2, 4.0.2, 4.1.2, 4.2.0, or later to address this vulnerability.

Affected Software

4 affected components
Apache Apache Kafka<=3.9.1, <=4.0.1, <=4.1.1
Apache Kafka>=2.8.0<3.9.2
Apache Kafka>=4.0.0<4.0.2
Apache Kafka>=4.1.0<4.1.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Apache Kafka to a version that resolves this vulnerability.

    Fixed in 3.9.2
  2. Upgrade

    Upgrade Apache Kafka to a version that resolves this vulnerability.

    Fixed in 4.0.2
  3. Upgrade

    Upgrade Apache Kafka to a version that resolves this vulnerability.

    Fixed in 4.1.2
  4. Upgrade

    Upgrade Apache Kafka to a version that resolves this vulnerability.

    Fixed in 4.2.0

Event History

Apr 7, 2026
CVE Published
via MITRE·01:07 PM
Data Sourced
via MITRE·01:07 PM
DescriptionWeakness
Data Sourced
via Red Hat·02:01 PM
DescriptionSeverityAffected Software
Data Sourced
via NVD·02:16 PM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-35554?

CVE-2026-35554 has been rated as a high severity vulnerability due to the risk of message corruption and misrouting in Apache Kafka Producer.

2

How do I fix CVE-2026-35554?

To fix CVE-2026-35554, upgrade your Apache Kafka client to the latest version that addresses this race condition.

3

What versions of Apache Kafka are affected by CVE-2026-35554?

CVE-2026-35554 affects Apache Kafka versions up to and including 3.9.1, 4.0.1, and 4.1.1.

4

What is the impact of CVE-2026-35554 on message delivery in Apache Kafka?

CVE-2026-35554 can cause messages to be silently delivered to incorrect topics due to a race condition in buffer pool management.

5

Is there a workaround for CVE-2026-35554?

There is no official workaround for CVE-2026-35554, and upgrading to a patched version is recommended to mitigate the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203