CVE-2025-27817
possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client.
Technology
Apache Kafka
CVSS Score
7.5 / 10.0
Affected Versions
>=3.1.0 <3.9.1
Upstream Fix
See upstream advisory
Published
June 10, 2025
OSSeva Coverage
Fixed upstream
Description
A possible arbitrary file read and SSRF vulnerability has been identified in Apache Kafka Client. Apache Kafka Clients accept configuration data for setting the SASL/OAUTHBEARER connection with the brokers, including "sasl.oauthbearer.token.endpoint.url" and "sasl.oauthbearer.jwks.endpoint.url". Apache Kafka allows clients to read an arbitrary file and return the content in the error log, or sending requests to an unintended location. In applications where Apache Kafka Clients configurations can be specified by an untrusted party, attackers may use the "sasl.oauthbearer.token.endpoint.url" and "sasl.oauthbearer.jwks.endpoint.url" conf
Is your Apache Kafka deployment affected?
If you're running >=3.1.0 <3.9.1, you need this patch. Book a discovery call to get covered.