Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15911

Опубликовано: 01 окт. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.

A flaw was found in confluent-kafka. The HashiCorp Vault Key Management Service (KMS) integration fails to properly validate Transport Layer Security (TLS) certificates by default. A remote attacker able to intercept network traffic could exploit this flaw to intercept and decrypt sensitive data or tamper with communications between the client and the Vault service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Satellite 6satellite/iop-advisor-backend-rhel9Affected
Red Hat Satellite 6satellite/iop-host-inventory-rhel9Affected
Red Hat Satellite 6satellite/iop-insights-engine-rhel9Affected
Red Hat Satellite 6satellite/iop-puptoo-rhel9Affected
Red Hat Satellite 6satellite/iop-yuptoo-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-295
https://bugzilla.redhat.com/show_bug.cgi?id=2544809confluent-kafka: confluent-kafka: Information disclosure via improper TLS certificate validation in HashiCorp Vault integration

EPSS

Процентиль: 9%
0.00202
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
nvd
3 дня назад

Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.

CVSS3: 7.4
github
3 дня назад

Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.

EPSS

Процентиль: 9%
0.00202
Низкий

7.4 High

CVSS3