Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-27817

possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client.

Technology

Apache Kafka

CVSS Score

7.5 / 10.0

Affected Versions

>=3.1.0 <3.9.1

Upstream Fix

See upstream advisory

Published

June 10, 2025

OSSeva Coverage

Fixed upstream

Description

A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including "sasl.oauthbearer.token.endpoint.url" and "sasl.oauthbearer.jwks.endpoint.url". Apache Kafka allows clients to read an arbitrary file and return the content in the error log, or sending requests to an unintended location. In applications where Apache Kafka Clients configurations can be specified by an untrusted party, attackers may use the "sasl.oauthbearer.token.endpoint.url" and "sasl.oauthbearer.jwks.endpoint.url" conf

Is your Apache Kafka deployment affected?

If you're running >=3.1.0 <3.9.1, you need this patch. Book a discovery call to get covered.