StackRadar

CVE-2026-33558

Medium

Advisory

Published 20 Apr 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
5.3
base score, highest
EPSS
0.006
48th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
160
of 17,781 indexed, latest versions
Container images
151
deployed by those charts
Fix available
3 of 3
affected packages

Apache Kafka, Apache Kafka Clients: Information Exposure Through Network Client Log Output

Carried by container images the latest versions of 160 of 17,781 indexed charts deploy, on 151 images.

Affected packageAffected versionsFixed inImages
kafka-clientsmaven0.11.0.0, 0.11.0.3, 1.0.1, 1.1.0+38 more3.9.2, 4.0.1151
kafkabitnami2.8.1-150, 3.4.0-2, 3.5.0-03.9.23
Apache Kafkabitnami3.5.03.9.21
OSV records
BIT-kafka-2026-33558GHSA-wf66-mphr-4c4r

Charts affected

160 by stars
ChartLatestAffected imagesRadar Score
shenyutest-helm2.4.211 of 2See more

shenyu test-helm 2.4.21

1 of the 2 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.4.20bd3b25c4be4
kafka-clients@2.3.1
3.9.2

Open the chart page →

12,513
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
kafka-clients@3.2.0
3.9.2
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
kafka-clients@3.2.0
3.9.2
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
kafka-clients@3.2.0
3.9.2
thingsboard/tb-node:3.4.1645f43b688f7
kafka-clients@3.2.0
3.9.2

Open the chart page →

25,394
hermestoukVerified publisher0.6.01 of 3See more

hermes touk 0.6.0

1 of the 3 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-kafkasql:2.1.0.Finala97d67487532
kafka-clients@2.7.0
3.9.2

Open the chart page →

12,455
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
kafka-clients@3.7.1
3.9.2

Open the chart page →

2,144
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
kafka-clients@3.9.1
3.9.2

Open the chart page →

5,484
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
kafka-clients@2.8.2
3.9.2

Open the chart page →

9,397
webhookie-allwebhookie0.1.21 of 3See more

webhookie-all webhookie 0.1.2

1 of the 3 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
quay.io/keycloak/keycloak:14.0.03029dc0f1d38
kafka-clients@2.7.0
3.9.2

Open the chart page →

28,605
apicurio-registry-sqlwitcom-gmbh0.1.01 of 1See more

apicurio-registry-sql witcom-gmbh 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
apicurio/apicurio-registry-jpa:1.3.2.Final44eeddd3562c
kafka-clients@2.5.0
3.9.2

Open the chart page →

3,424
opendistro-eswitcom-gmbh1.13.31 of 3See more

opendistro-es witcom-gmbh 1.13.3

1 of the 3 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
amazon/opendistro-for-elasticsearch:1.13.32acfa1dcc5f8
kafka-clients@2.5.0
3.9.2

Open the chart page →

5,806
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-33558.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
kafka-clients@3.7.1
3.9.2

Open the chart page →

9,381

Container images carrying it

151 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
quay.io/strimzi/operator:0.36.1e9e03b31007c
kafka-clients@3.5.1
3.9.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.