StackRadar

CVE-2026-33558

Medium

Advisory

Published 20 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
160
of 17,781 indexed, latest versions
Container images
151
deployed by those charts
Fix available
3 of 3
affected packages

Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output

Carried by container images the latest versions of 160 of 17,781 indexed charts deploy, on 151 images.

Affected packageAffected versionsFixed inImages
kafka-clientsmaven0.11.0.0, 0.11.0.3, 1.0.1, 1.1.0+38 more3.9.2, 4.0.1151
kafkabitnami2.8.1-150, 3.4.0-2, 3.5.0-03.9.23
Apache Kafkabitnami3.5.03.9.21
OSV records
BIT-kafka-2026-33558GHSA-wf66-mphr-4c4r

Charts affected

160 by stars
ChartLatestAffected imagesRadar Score
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
kafka-clients@2.3.1
3.9.2

Open the chart page →

12,513
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
kafka-clients@3.2.0
3.9.2
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
kafka-clients@3.2.0
3.9.2
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
kafka-clients@3.2.0
3.9.2
thingsboard/tb-node:3.4.1645f43b688f7
kafka-clients@3.2.0
3.9.2

Open the chart page →

25,394
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
kafka-clients@2.7.0
3.9.2

Open the chart page →

12,455
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
kafka-clients@3.7.1
3.9.2

Open the chart page →

2,144
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
kafka-clients@3.9.1
3.9.2

Open the chart page →

5,484
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
kafka-clients@2.8.2
3.9.2

Open the chart page →

9,397
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
kafka-clients@2.7.0
3.9.2

Open the chart page →

28,605
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
kafka-clients@2.5.0
3.9.2

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
kafka-clients@2.5.0
3.9.2

Open the chart page →

5,806
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
kafka-clients@3.7.1
3.9.2

Open the chart page →

9,381

Container images carrying it

151 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
opensearchproject/opensearch:2.14.0466a49f379bb
kafka-clients@3.7.0
3.9.2
1
opensearchproject/opensearch:3.1.0474ea3fdf25d
kafka-clients@4.0.0
4.0.1
1
opensearchproject/opensearch:2.12.0645d3d9390ad
kafka-clients@3.5.1
3.9.2
1
opensearchproject/opensearch:2.19.269588c664014
kafka-clients@3.7.1
3.9.2
1
opensearchproject/opensearch:3.3.2798cf28e226a
kafka-clients@4.0.0
4.0.1
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
kafka-clients@3.5.1
3.9.2
1
openwhisk/invoker:1.0.0f5831ec85525
kafka-clients@2.4.0
3.9.2
1
openzipkin/zipkin:2.24197a9692f6a9
kafka-clients@3.6.0
3.9.2
1
openzipkin/zipkin:2.21.060c3970df479
kafka-clients@2.4.1
3.9.2
1
openzipkin/zipkin-gcp:0.15.2b5d51d1144e2
kafka-clients@2.3.0
3.9.2
1
pcarrascoponce/planner:v1.0981fc482442c
kafka-clients@3.0.0
3.9.2
1
radarbase/kafka-manager:1.3.3.181d2af7dd5a4e
kafka-clients@1.1.0
3.9.2
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
kafka-clients@3.0.0
3.9.2
1
seataio/seata-server:latest703b5de7f1a6
kafka-clients@3.1.2
3.9.2
1
seataio/seata-server:1.5.1ee1ed55f4144
kafka-clients@2.6.3
3.9.2
1
seldonio/apife:0.2.7ba81b17f00eb
kafka-clients@0.11.0.0
3.9.2
1
seldonio/apife:0.3.1eea0d3f578ca
kafka-clients@0.11.0.0
3.9.2
1
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
kafka-clients@4.0.0
4.0.1
1
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
kafka-clients@3.2.0
3.9.2
1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
kafka-clients@3.2.0
3.9.2
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
kafka-clients@3.2.0
3.9.2
1
thingsboard/tb-node:3.4.1645f43b688f7
kafka-clients@3.2.0
3.9.2
1
thingsboard/tb-node:3.6.0f40a542832c4
kafka-clients@3.2.0
3.9.2
1
thingsboard/tb-postgres:latest2d17e4e36edc
kafka-clients@3.9.1
3.9.2
1
traccar/traccar:6.7-alpine621c8d6d46fd
kafka-clients@4.0.0
4.0.1
1
trinodb/trino:45038c6f24ab1a4
kafka-clients@3.7.0
3.9.2
1
trinodb/trino:405ee80ab5eeab2
kafka-clients@2.4.1
3.9.2
1
vitalii1992/analytics-service:latest8e798836ecea
kafka-clients@3.4.0
3.9.2
1
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
kafka-clients@3.4.0
3.9.2
1
vlebediantsev/logic-ms:latestdf8bf38c535b
kafka-clients@3.1.1
3.9.2
1
vlebediantsev/registration-ms-final:latest427af418b75e
kafka-clients@3.1.1
3.9.2
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
kafka-clients@3.1.1
3.9.2
1
wazuh/wazuh-indexer:4.14.49c344d2b1757
kafka-clients@3.9.1
3.9.2
1
wazuh/wazuh-indexer:4.11.1a7a2076b167e
kafka-clients@3.7.1
3.9.2
1
wazuh/wazuh-indexer:4.14.3b149b30da686
kafka-clients@3.9.1
3.9.2
1
xeotek/kadeck:4.2.94c6b04d9ce55
kafka-clients@3.3.1
3.9.2
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
kafka-clients@3.6.1
3.9.2
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
kafka-clients@3.3.2
3.9.2
1
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
kafka-clients@4.0.0
4.0.1
1
ghcr.io/eshepelyuk/dckr/cmak-3.0.0.6:1.2.090a34412c6b5
kafka-clients@2.4.1
3.9.2
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
kafka-clients@2.8.1
3.9.2
1
ghcr.io/kubelauncher/kafka43e1085cd0a8
kafka-clients@3.9.0
3.9.2
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
kafka-clients@2.8.1
3.9.2
1
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
kafka-clients@3.7.0
3.9.2
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
kafka-clients@3.7.2
3.9.2
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
kafka-clients@2.8.2
3.9.2
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
kafka-clients@3.5.1
3.9.2
1
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
kafka-clients@2.7.0
3.9.2
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
kafka-clients@3.3.2
3.9.2
1
quay.io/strimzi/operator:0.45.158c727cd2e68
kafka-clients@3.9.1
3.9.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.