StackRadar

CVE-2025-27817

High

Advisory

Published 10 Jun 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.688
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
65
of 17,781 indexed, latest versions
Container images
66
deployed by those charts
Fix available
3 of 3
affected packages

Apache Kafka Client: Arbitrary file read and SSRF vulnerability

Carried by container images the latest versions of 65 of 17,781 indexed charts deploy, on 66 images.

Affected packageAffected versionsFixed inImages
kafka-clientsmaven3.1.0, 3.1.1, 3.1.2, 3.2.0+13 more3.9.166
kafkabitnami3.4.0-2, 3.5.0-03.9.12
Apache Kafkabitnami3.5.03.9.11
OSV records
BIT-kafka-2025-27817GHSA-vgq5-3255-v292

Charts affected

65 by stars
ChartLatestAffected imagesRadar Score
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
kafka-clients@3.1.1
3.9.1

Open the chart page →

5,916
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
kafka-clients@3.1.1
3.9.1

Open the chart page →

5,873
apicurioone-acre-fundVerified publisher2.3.02 of 5See more

apicurio one-acre-fund 2.3.0

2 of the 5 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
kafka-clients@3.3.2
3.9.1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
kafka-clients@3.3.2
3.9.1

Open the chart page →

18,667
bpjstk-serviceopenshift1.0.01 of 6See more

bpjstk-service openshift 1.0.0

1 of the 6 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
andrianrf/backoffice-be:latest6036614803d4
kafka-clients@3.1.2
3.9.1

Open the chart page →

34,671
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
kafka-clients@3.8.1
3.9.1

Open the chart page →

7,792
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
kafka-clients@3.5.1
3.9.1

Open the chart page →

1,190
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
kafka-clients@3.7.0
3.9.1

Open the chart page →

1,753
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
kafka-clients@3.7.0
3.9.1

Open the chart page →

21,211
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
kafka-clients@3.5.0
3.9.1

Open the chart page →

1,597
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
kafka-clients@3.1.2
3.9.1

Open the chart page →

4,245
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.54 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

4 of the 6 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
kafka-clients@3.1.2
3.9.1
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
kafka-clients@3.1.2
3.9.1
fimperato/static-src-info-data-transformation:1.0.5-RELEASEdf05c388ea6c
kafka-clients@3.1.2
3.9.1
fimperato/static-src-people-detection:1.1.5-RELEASEc0cfaca070d9
kafka-clients@3.1.2
3.9.1

Open the chart page →

13,646
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
kafka-clients@3.7.2
3.9.1

Open the chart page →

4,674
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
kafka-clients@3.2.0
3.9.1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
kafka-clients@3.2.0
3.9.1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
kafka-clients@3.2.0
3.9.1
thingsboard/tb-node:3.4.1645f43b688f7
kafka-clients@3.2.0
3.9.1

Open the chart page →

25,394
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
kafka-clients@3.7.1
3.9.1

Open the chart page →

2,144
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2025-27817.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
kafka-clients@3.7.1
3.9.1

Open the chart page →

9,381

Container images carrying it

66 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
trinodb/trino:45038c6f24ab1a4
kafka-clients@3.7.0
3.9.1
1
vitalii1992/analytics-service:latest8e798836ecea
kafka-clients@3.4.0
3.9.1
1
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
kafka-clients@3.4.0
3.9.1
1
vlebediantsev/logic-ms:latestdf8bf38c535b
kafka-clients@3.1.1
3.9.1
1
vlebediantsev/registration-ms-final:latest427af418b75e
kafka-clients@3.1.1
3.9.1
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
kafka-clients@3.1.1
3.9.1
1
wazuh/wazuh-indexer:4.11.1a7a2076b167e
kafka-clients@3.7.1
3.9.1
1
xeotek/kadeck:4.2.94c6b04d9ce55
kafka-clients@3.3.1
3.9.1
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
kafka-clients@3.6.1
3.9.1
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
kafka-clients@3.3.2
3.9.1
1
ghcr.io/kubelauncher/kafka43e1085cd0a8
kafka-clients@3.9.0
3.9.1
1
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
kafka-clients@3.7.0
3.9.1
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
kafka-clients@3.7.2
3.9.1
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
kafka-clients@3.5.1
3.9.1
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
kafka-clients@3.3.2
3.9.1
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
kafka-clients@3.5.1
3.9.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.