StackRadar

CVE-2025-27819

High

Advisory

Published 10 Jun 2025In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
8.8
base score, highest
EPSS
0.010
62nd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
21
of 17,781 indexed, latest versions
Container images
11
deployed by those charts
Fix available
3 of 5
affected packages

Apache Kafka Deserialization of Untrusted Data vulnerability

Carried by container images the latest versions of 21 of 17,781 indexed charts deploy, on 11 images.

Affected packageAffected versionsFixed inImages
kafka_2.11maven0.10.1.1, 2.0.0, 2.0.1-cp1, 2.4.0no fix listed4
kafka_2.12maven2.5.1, 2.8.1-javadoc, 3.3.13.4.03
kafka_2.13maven2.8.1-test, 3.3.03.4.02
kafka_2.10maven0.8.2.2no fix listed1
kafkabitnami2.8.1-150, 3.4.0-23.4.12
OSV records
BIT-kafka-2025-27819GHSA-mcwh-c9pg-xw43

Charts affected

21 by stars
ChartLatestAffected imagesRadar Score
druidwiremindVerified publisher1.22.11 of 3See more

druid wiremind 1.22.1

1 of the 3 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
apache/druid:29.0.10cef139b6bf1
kafka_2.11@2.0.0
no fix listed

Open the chart page →

7,930
kubernetes-loggingkubernetes-logging4.8.01 of 6See more

kubernetes-logging kubernetes-logging 4.8.0

1 of the 6 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
kafka_2.12@3.3.1
3.4.0

Open the chart page →

10,530
clearml-servingallegroaiVerified publisher1.6.21 of 9See more

clearml-serving allegroai 1.6.2

1 of the 9 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
kafka@3.4.0-2
3.4.1

Open the chart page →

17,877
logstashromanow-helm-chartsVerified publisher1.5.01 of 1See more

logstash romanow-helm-charts 1.5.0

1 of the 1 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
library/logstash:7.17.817a4f64e9cf5
kafka_2.12@2.5.1
3.4.0

Open the chart page →

7,529
airports-kafkaairports-kafka0.1.01 of 2See more

airports-kafka airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
kafka_2.13@2.8.1-test
3.4.0

Open the chart page →

4,547
tsoragecetic0.4.111 of 8See more

tsorage cetic 0.4.11

1 of the 8 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
confluentinc/cp-kafka:5.0.1c87b1c07fb53
kafka_2.11@2.0.1-cp1
no fix listed

Open the chart page →

12,018
event-store-servicechoerodon0.8.01 of 2See more

event-store-service choerodon 0.8.0

1 of the 2 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
choerodon/event-store-service:0.8.03c94c97f6f69
kafka_2.11@0.10.1.1
no fix listed

Open the chart page →

9,808
prestocloudnativeapp0.1.11 of 1See more

presto cloudnativeapp 0.1.1

1 of the 1 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
bivas/presto:0.19605545994f806
kafka_2.10@0.8.2.2
no fix listed

Open the chart page →

7,226
apache-ranger-admindata-platform-stableVerified publisher0.2.01 of 2See more

apache-ranger-admin data-platform-stable 0.2.0

1 of the 2 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
kafka_2.11@2.4.0
no fix listed

Open the chart page →

8,245
kafkagengxiankun-charts0.2.01 of 1See more

kafka gengxiankun-charts 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
kafka_2.13@2.8.1-test
3.4.0

Open the chart page →

4,547
helm-airportshelm-airports0.1.01 of 7See more

helm-airports helm-airports 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
kafka_2.13@2.8.1-test
3.4.0

Open the chart page →

12,696
airports-kafkahelm-airports-dan0.1.01 of 2See more

airports-kafka helm-airports-dan 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
kafka_2.13@2.8.1-test
3.4.0

Open the chart page →

4,547
helm-airportshelm-airports-dan0.1.01 of 7See more

helm-airports helm-airports-dan 0.1.0

1 of the 7 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
kafka_2.13@2.8.1-test
3.4.0

Open the chart page →

5,573
airports-kafkahelm-airports-kafka0.1.01 of 2See more

airports-kafka helm-airports-kafka 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
kafka_2.13@2.8.1-test
3.4.0

Open the chart page →

4,547
account-lookup-servicemojaloop13.0.01 of 4See more

account-lookup-service mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
kafka_2.13@3.3.0
3.4.0

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.01 of 4See more

account-lookup-service-admin mojaloop 13.0.0

1 of the 4 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
kafka_2.13@3.3.0
3.4.0

Open the chart page →

11,695
admin-api-svcmojaloop12.0.01 of 4See more

admin-api-svc mojaloop 12.0.0

1 of the 4 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
kafka_2.13@3.3.0
3.4.0

Open the chart page →

12,108
backendmojaloop0.1.01 of 6See more

backend mojaloop 0.1.0

1 of the 6 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
kafka_2.12@2.8.1-javadoc
kafka@2.8.1-150
3.4.0
3.4.1

Open the chart page →

16,198
fspiop-transfer-api-svcmojaloop12.0.11 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

1 of the 3 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
kafka_2.13@3.3.0
3.4.0

Open the chart page →

11,479
mojaloopmojaloop14.0.01 of 6See more

mojaloop mojaloop 14.0.0

1 of the 6 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
solsson/kafka:latest41e5d8f6f290
kafka_2.13@3.3.0
3.4.0

Open the chart page →

19,226
kafka-helm-chartnotesprojectchart0.1.01 of 1See more

kafka-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-27819.

Container imageDigestPackageFixed in
wurstmeister/kafka:latest2d4bbf9cc83d
kafka_2.13@2.8.1-test
3.4.0

Open the chart page →

4,547

Container images carrying it

11 by charts deploying them

A fixed version is listed for 3 of the 5 affected packages.

Container imageDigestPackageFixed inUsed by
wurstmeister/kafka:latest2d4bbf9cc83d
kafka_2.13@2.8.1-test
3.4.0
7
solsson/kafka:latest41e5d8f6f290
kafka_2.13@3.3.0
3.4.0
5
apache/druid:29.0.10cef139b6bf1
kafka_2.11@2.0.0
no fix listed
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
kafka@3.4.0-2
3.4.1
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
kafka_2.12@2.8.1-javadoc
kafka@2.8.1-150
3.4.0
3.4.1
1
bivas/presto:0.19605545994f806
kafka_2.10@0.8.2.2
no fix listed
1
choerodon/event-store-service:0.8.03c94c97f6f69
kafka_2.11@0.10.1.1
no fix listed
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
kafka_2.11@2.0.1-cp1
no fix listed
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
kafka_2.11@2.4.0
no fix listed
1
library/logstash:7.17.817a4f64e9cf5
kafka_2.12@2.5.1
3.4.0
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
kafka_2.12@3.3.1
3.4.0
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.