Back to Vulnerability Directory
MEDIUMFixed upstream

CVE-2026-33558

Apache Kafka Clients: NetworkClient DEBUG logging exposes credentials

Technology

Apache Kafka

CVSS Score

5.3 / 10.0

Affected Versions

Kafka Clients 0.11.0 to 3.9.1; 4.0.0

Upstream Fix

3.9.2; 4.0.1; 4.1.0

Published

April 20, 2026

OSSeva Coverage

Fixed upstream

Description

At DEBUG log level the NetworkClient component logs whole requests and responses, including SaslAuthenticate, AlterUserScramCredentials, AlterConfigs and the delegation token requests and responses, so credentials and tokens can end up in the logs. The default level is INFO. Fixed in 3.9.2, 4.0.1 and 4.1.0; keeping the NetworkClient class at INFO or higher avoids it.

Upstream record: NVD · CVE.org

Is your Apache Kafka deployment affected?

If you're running Kafka Clients 0.11.0 to 3.9.1; 4.0.0, you need this patch. Book a discovery call to get covered.