Количество 3
Количество 3
CVE-2026-15911
A flaw was found in confluent-kafka. The HashiCorp Vault Key Management Service (KMS) integration fails to properly validate Transport Layer Security (TLS) certificates by default. A remote attacker able to intercept network traffic could exploit this flaw to intercept and decrypt sensitive data or tamper with communications between the client and the Vault service.
CVE-2026-15911
Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.
GHSA-r743-crv8-m3qr
Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-15911 A flaw was found in confluent-kafka. The HashiCorp Vault Key Management Service (KMS) integration fails to properly validate Transport Layer Security (TLS) certificates by default. A remote attacker able to intercept network traffic could exploit this flaw to intercept and decrypt sensitive data or tamper with communications between the client and the Vault service. | CVSS3: 7.4 | 0% Низкий | 4 дня назад | |
CVE-2026-15911 Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation. | CVSS3: 7.4 | 0% Низкий | 4 дня назад | |
GHSA-r743-crv8-m3qr Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation. | CVSS3: 7.4 | 0% Низкий | 4 дня назад |
Уязвимостей на страницу