RHSA-2026:54435: Important: Streams for Apache Kafka 3.2.1 release and security update
Important: Streams for Apache Kafka 3.2.1 release and security update
Other sources
Red Hat Streams for Apache Kafka, based on the Apache Kafka project, offers a distributedbackbone that allows microservices and other applications to share data withextremely high throughput and extremely low latency.This release of Red Hat Streams for Apache Kafka 3.2.1 serves as a replacement for Red Hat Streams for Apache Kafka 3.2.0, and includes security and bug fixes, and enhancements.Security Fix(es): golang-github-danielqsj-kafkaexporter: Go crypto/tls: Denial of Service via multiple TLS 1.3 key update messages (CVE-2026-32283) quarkus-vertx-http: io.quarkus:quarkus-vertx-http: Authorization bypass via semicolons in HTTP requests (CVE-2026-39852) kafka-clients: Apache Kafka Clients: Information disclosure and data corruption due to race condition in producer buffer management (CVE-2026-35554) log4j-layout-template-json: Apache Log4j JsonTemplateLayout: Denial of Service via invalid JSON output (CVE-2026-34481) log4j-core: Apache Log4j Core: Invalid XML output causes denial of service in logging (CVE-2026-34480) log4j-core: Apache Log4j Core: Log injection via CRLF sequences due to configuration attribute renames (CVE-2026-34478) netty-codec-dns: Netty: High integrity impact due to improper DNS domain name constraint enforcement (CVE-2026-42579) netty-codec-http: Netty: Incorrect HTTP response parsing leads to data confusion (CVE-2026-42584) netty-codec-http: Netty: HTTP Request Smuggling due to improper handling of conflicting HTTP/1.0 headers (CVE-2026-42581) netty-handler-proxy: Netty: HTTP Header Injection via HttpProxyHandler Disabled Validation (CVE-2026-42578) netty-codec-http: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587) netty-codec-http2: Netty: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587) netty-codec: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder (CVE-2026-42583) netty-codec-compression: Netty: Denial of Service via excessive memory allocation in LZ4FrameDecoder (CVE-2026-42583) next: Next.js: Authorization bypass via crafted query parameters (CVE-2026-44574) next: Next.js: Denial of Service via crafted POST requests to server actions (CVE-2026-44579) next: Next.js: Denial of Service via Image Optimization API (CVE-2026-44577) next: Next.js: Information disclosure due to middleware bypass in Pages Router with i18n (CVE-2026-44573) next: Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests (CVE-2026-44578) next: Next.js: Information disclosure via security fix bypass in middleware with Turbopack (CVE-2026-45109) next: Next.js: Unauthorized access to protected content via middleware bypass (CVE-2026-44575) quarkus-vertx-http: Quarkus: Authorization bypass in HTTP path-based policies via encoded characters (CVE-2026-50559) golang-github-danielqsj-kafkaexporter: golang.org/x/net/idna: Privilege escalation via incorrect Punycode label processing (CVE-2026-39821) vertx-core: eclipse-vertx/vert.x: Denial of Service via TLS handshake with wildcard server name (CVE-2026-6860) netty-handler: netty-handler: IPv6 subnet rule bypass due to incorrect masking operation (CVE-2026-44249) netty-codec-haproxy: Netty-codec-haproxy: Denial of Service via malformed HAProxy message (CVE-2026-44893) netty-codec-http2: netty-codec-http2: Denial of Service due to resource leak (CVE-2026-48043) netty-codec-haproxy: Netty HAProxy PROXY protocol v2 codec: Denial of Service via memory leak from crafted PROXY protocol headers (CVE-2026-48059) netty-resolver-dns: Netty has Insufficient Bailiwick Validation for NS Records (CVE-2026-47691) netty-resolver-dns: Netty: Information disclosure and data manipulation due to improper CNAME record validation (CVE-2026-45674) netty-handler: Netty: Denial of Service due to eager buffer allocation in TLS handshake (CVE-2026-45416) golang-github-danielqsj-kafkaexporter: Go net package: Denial of Service via long CNAME response in LookupCNAME (CVE-2026-33811) cluster-operator: Cross-namespace privilege escalation via Kafka.spec.entityOperator.watchedNamespace in Strimzi (CVE-2026-55225) micrometer-core: Micrometer: Denial of Service via specially crafted HTTP requests (CVE-2026-40984) micrometer-core: Micrometer: Denial of Service via specially crafted gRPC requests (CVE-2026-40983) golang-github-danielqsj-kafkaexporter: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries (CVE-2026-27145) jackson-databind: jackson-databind: Arbitrary code execution via PolymorphicTypeValidator bypass (CVE-2026-54512) jackson-databind: Jackson-databind: Denial of Service via deeply nested JSON processing (CVE-2026-50193) golang-github-danielqsj-kafkaexporter: Golang MIME: Denial of Service via maliciously-crafted MIME header (CVE-2026-42504) jackson-databind: Jackson-databind: Security bypass allows arbitrary code execution (CVE-2026-54513) vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects (CVE-2026-15075) vertx-core-logging: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects (CVE-2026-15075) smallrye-mutiny-vertx-core: Eclipse Vert.x: Information disclosure via improper handling of HTTP 30x redirects (CVE-2026-15075) js-yaml: js-yaml: Denial of Service via crafted YAML documents (CVE-2026-59869) resteasy-reactive-client-processor: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308) resteasy-reactive-common-processor: Quarkus REST - Unbounded multipart MIME part-header accumulation allows remote OOM denial of service (CVE-2026-16308) vertx-web-common: Eclipse Vert.x Web Client: Information disclosure via improper cookie domain validation (CVE-2026-15076) netty-codec-http: Netty: Denial of Service via SPDY header decompression amplification (CVE-2026-55833) netty-codec-http: Netty: Denial of Service via SPDY SETTINGS frame processing (CVE-2026-55831) netty-codec-http: Netty: Denial of Service via memory exhaustion in SPDY-to-HTTP codec (CVE-2026-56745) netty-codec-http: Netty: Security control bypass allows unauthorized requests via null origin header (CVE-2026-56746) netty-codec-http2: Netty: Denial of Service via HTTP/2 DATA frame memory leak (CVE-2026-56819) netty-codec-http: Netty: Memory exhaustion in netty-codec-http (decompression bomb) (CVE-2026-59899) netty-codec-compression: Netty: Infinite loop in netty-codec-compression (bzip2) (CVE-2026-59901) jetty-server: Eclipse Jetty: Information disclosure due to retained HTTP/1.1 trailers across connections (CVE-2026-10051) postcss: PostCSS: Information disclosure via crafted sourceMappingURL (CVE-2026-69153) next: Next.js: Denial of Service via excessive memory consumption in Server Actions (CVE-2026-64646) next: Next.js: Information disclosure via server-side fetch cache (CVE-2026-64648) next: Next.js: Server-Side Request Forgery vulnerability (CVE-2026-64645) next: Next.js: Server-Side Request Forgery via malicious host redirection in Server Actions (CVE-2026-64649) next: Next.js: Denial of Service via malicious image optimization (CVE-2026-64644) next: Next.js: Denial of Service via crafted requests to App Router with Server Actions (CVE-2026-64641) netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability dompurify: DOMPurify: Cross-site scripting vulnerability allows code execution (CVE-2026-49978)
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Red Hat Streams for Apache Kafkato a version that resolves this vulnerability.Fixed in 3.2.1 - Operational
Before updating, ensure all previously released errata relevant to your system have been applied.
Event History
Frequently Asked Questions
What is the severity of RHSA-2026:54435?
The severity of RHSA-2026:54435 is rated as high with a score of 7.
What vulnerabilities does RHSA-2026:54435 address?
RHSA-2026:54435 addresses important security issues found in Streams for Apache Kafka 3.2.1.
How do I fix RHSA-2026:54435?
To fix RHSA-2026:54435, update your software to the latest version of Streams for Apache Kafka as per the provided security update.
Who is affected by RHSA-2026:54435?
RHSA-2026:54435 primarily affects users of Red Hat JBoss Middleware who utilize Streams for Apache Kafka 3.2.1.
When was RHSA-2026:54435 published?
RHSA-2026:54435 was published on August 12, 2026.