StackRadar

CVE-2026-33558

Medium

Advisory

Published 20 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
160
of 17,781 indexed, latest versions
Container images
151
deployed by those charts
Fix available
3 of 3
affected packages

Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output

Carried by container images the latest versions of 160 of 17,781 indexed charts deploy, on 151 images.

Affected packageAffected versionsFixed inImages
kafka-clientsmaven0.11.0.0, 0.11.0.3, 1.0.1, 1.1.0+38 more3.9.2, 4.0.1151
kafkabitnami2.8.1-150, 3.4.0-2, 3.5.0-03.9.23
Apache Kafkabitnami3.5.03.9.21
OSV records
BIT-kafka-2026-33558GHSA-wf66-mphr-4c4r

Charts affected

160 by stars
ChartLatestAffected imagesRadar Score
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
kafka-clients@2.3.1
3.9.2

Open the chart page →

12,513
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
kafka-clients@3.2.0
3.9.2
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
kafka-clients@3.2.0
3.9.2
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
kafka-clients@3.2.0
3.9.2
thingsboard/tb-node:3.4.1645f43b688f7
kafka-clients@3.2.0
3.9.2

Open the chart page →

25,394
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
kafka-clients@2.7.0
3.9.2

Open the chart page →

12,455
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
kafka-clients@3.7.1
3.9.2

Open the chart page →

2,144
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
kafka-clients@3.9.1
3.9.2

Open the chart page →

5,484
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
kafka-clients@2.8.2
3.9.2

Open the chart page →

9,397
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
kafka-clients@2.7.0
3.9.2

Open the chart page →

28,605
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
kafka-clients@2.5.0
3.9.2

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
kafka-clients@2.5.0
3.9.2

Open the chart page →

5,806
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
kafka-clients@3.7.1
3.9.2

Open the chart page →

9,381

Container images carrying it

151 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
apache/skywalking-oap-server:8.9.1b4ec8c18d079
kafka-clients@2.4.1
3.9.2
1
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
kafka-clients@2.5.0
3.9.2
1
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
kafka-clients@2.7.0
3.9.2
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
kafka-clients@3.3.2
3.9.2
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
kafka-clients@3.3.2
3.9.2
1
arturisimo/planner:v1.0fff9de644941
kafka-clients@3.0.0
3.9.2
1
assistiot/automated_configuration:latest23f195a7a26a
kafka-clients@2.8.1
3.9.2
1
assistiot/cybersecurity-monitoring_id-elk:latestba1d85ec3739
kafka-clients@2.5.0
3.9.2
1
assistiot/identity-manager_kc:latest0df4b4fa899a
kafka-clients@3.1.0
3.9.2
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
Apache Kafka@3.5.0
kafka@3.5.0-0
kafka-clients@3.5.0
3.9.2
3.9.2
3.9.2
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
kafka@3.4.0-2
kafka-clients@3.4.0
3.9.2
3.9.2
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
kafka@2.8.1-150
kafka-clients@2.8.1
3.9.2
3.9.2
1
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
kafka-clients@3.7.1
3.9.2
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
kafka-clients@3.9.0
3.9.2
1
conductoross/conductor:3.31.09fba127693e6
kafka-clients@3.7.2
3.9.2
1
confluentinc/cp-kafka:5.0.1c87b1c07fb53
kafka-clients@2.0.1-cp1
3.9.2
1
egdsandaru/apache-ranger-admin:1.0.0681baa1926f4
kafka-clients@2.4.0
3.9.2
1
expediagroup/pitchfork:1.314f2cf61e7de9
kafka-clients@3.0.0
3.9.2
1
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
kafka-clients@3.1.2
3.9.2
1
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
kafka-clients@3.1.2
3.9.2
1
fimperato/static-src-info-data-transformation:1.0.5-RELEASEdf05c388ea6c
kafka-clients@3.1.2
3.9.2
1
fimperato/static-src-people-detection:1.1.5-RELEASEc0cfaca070d9
kafka-clients@3.1.2
3.9.2
1
flowable/flowable-rest:7.1.0b7ae287502cd
kafka-clients@3.7.1
3.9.2
1
graviteeio/ae-engine:3.0.24140932887e0
kafka-clients@3.7.1
3.9.2
1
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
kafka-clients@3.1.2
3.9.2
1
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
kafka-clients@3.1.2
3.9.2
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
kafka-clients@3.0.1
3.9.2
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
kafka-clients@3.0.1
3.9.2
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
kafka-clients@3.0.1
3.9.2
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
kafka-clients@3.0.1
3.9.2
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
kafka-clients@3.0.1
3.9.2
1
gurolakman/ussigw-core:1.0.48739565c3ea2
kafka-clients@3.0.1
3.9.2
1
huertaslopez/i.huertas.2021-v.martinp.2021-planner:2.0.0e2c18bd65472
kafka-clients@3.0.0
3.9.2
1
hugohg34/planner:0.0.2171f61e8d7e2
kafka-clients@3.0.0
3.9.2
1
ibmcom/bai-elasticsearch-dev:19.0.25441dba2fa00
kafka-clients@1.0.1
3.9.2
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
kafka-clients@3.7.1
3.9.2
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
kafka-clients@3.7.0
3.9.2
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
kafka-clients@3.7.0
3.9.2
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
kafka-clients@3.7.0
3.9.2
1
library/logstash:7.17.817a4f64e9cf5
kafka-clients@2.5.1
3.9.2
1
library/logstash:9.1.233eae14f0867
kafka-clients@3.9.1
3.9.2
1
library/storm:2.4.0bd5d420506d6
kafka-clients@0.11.0.3
3.9.2
1
lightbend/cloudflow-operator:0.0.0-NIGHTLY011220202647f396de23
kafka-clients@2.5.0
3.9.2
1
lourdesmorente/new-planner:1.0.0608745878cdb
kafka-clients@3.0.0
3.9.2
1
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
kafka-clients@3.0.2
3.9.2
1
molynx/planner:v1441c9f52f092
kafka-clients@3.0.0
3.9.2
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
kafka-clients@2.2.0
3.9.2
1
opencord/ves-agent:1.0.04187e2a8c918
kafka-clients@1.1.0
3.9.2
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
kafka-clients@3.3.1
3.9.2
1
opensearchproject/opensearch:2.15.01963b3ece46d
kafka-clients@3.7.0
3.9.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.