Back to Vulnerability Directory
MEDIUMFixed upstream
CVE-2026-33558
Apache Kafka Clients: NetworkClient DEBUG logging exposes credentials
Technology
Apache Kafka
CVSS Score
5.3 / 10.0
Affected Versions
Kafka Clients 0.11.0 to 3.9.1; 4.0.0
Upstream Fix
3.9.2; 4.0.1; 4.1.0
Published
April 20, 2026
OSSeva Coverage
Fixed upstream
Description
At DEBUG log level the NetworkClient component logs whole requests and responses, including SaslAuthenticate, AlterUserScramCredentials, AlterConfigs and the delegation token requests and responses, so credentials and tokens can end up in the logs. The default level is INFO. Fixed in 3.9.2, 4.0.1 and 4.1.0; keeping the NetworkClient class at INFO or higher avoids it.
Is your Apache Kafka deployment affected?
If you're running Kafka Clients 0.11.0 to 3.9.1; 4.0.0, you need this patch. Book a discovery call to get covered.