StackRadar

CVE-2026-35554

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
127
of 17,781 indexed, latest versions
Container images
121
deployed by those charts
Fix available
1 of 1
affected package

Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition

Carried by container images the latest versions of 127 of 17,781 indexed charts deploy, on 121 images.

Affected packageAffected versionsFixed inImages
kafka-clientsmaven2.8.1, 2.8.2, 3.0.0, 3.0.1+21 more3.9.2, 4.0.2, 4.1.2121
OSV records
GHSA-5qcv-4rpc-jp93

Charts affected

127 by stars
ChartLatestAffected imagesRadar Score
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
kafka-clients@3.8.1
3.9.2

Open the chart page →

7,792
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
kafka-clients@3.0.1
3.9.2

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,100
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
kafka-clients@3.5.1
3.9.2

Open the chart page →

1,190
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
kafka-clients@4.0.0
4.0.2

Open the chart page →

71,208
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
kafka-clients@3.7.0
3.9.2

Open the chart page →

1,753
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
kafka-clients@3.0.0
3.9.2

Open the chart page →

27,537
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
pcarrascoponce/planner:v1.0981fc482442c
kafka-clients@3.0.0
3.9.2

Open the chart page →

27,558
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
kafka-clients@3.7.0
3.9.2

Open the chart page →

21,211
radar-kafkaradar-baseVerified publisher0.4.11 of 2See more

radar-kafka radar-base 0.4.1

1 of the 2 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
kafka-clients@4.0.0
4.0.2

Open the chart page →

4,219
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
kafka-clients@4.0.0
4.0.2

Open the chart page →

1,951
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
kafka-clients@3.5.0
3.9.2

Open the chart page →

1,597
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
kafka-clients@3.1.2
3.9.2

Open the chart page →

4,245
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
kafka-clients@3.0.1
3.9.2

Open the chart page →

8,804
strimzi-user-operatorspartan0.4.01 of 1See more

strimzi-user-operator spartan 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.45.158c727cd2e68
kafka-clients@3.9.1
3.9.2

Open the chart page →

1,836
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.54 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

4 of the 6 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
kafka-clients@3.1.2
3.9.2
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
kafka-clients@3.1.2
3.9.2
fimperato/static-src-info-data-transformation:1.0.5-RELEASEdf05c388ea6c
kafka-clients@3.1.2
3.9.2
fimperato/static-src-people-detection:1.1.5-RELEASEc0cfaca070d9
kafka-clients@3.1.2
3.9.2

Open the chart page →

13,646
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
kafka-clients@3.7.2
3.9.2

Open the chart page →

4,674
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
kafka-clients@2.8.2
3.9.2

Open the chart page →

4,240
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
kafka-clients@3.2.0
3.9.2
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
kafka-clients@3.2.0
3.9.2
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
kafka-clients@3.2.0
3.9.2
thingsboard/tb-node:3.4.1645f43b688f7
kafka-clients@3.2.0
3.9.2

Open the chart page →

25,394
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
kafka-clients@3.7.1
3.9.2

Open the chart page →

2,144
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
kafka-clients@3.9.1
3.9.2

Open the chart page →

5,484
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
kafka-clients@2.8.2
3.9.2

Open the chart page →

9,397
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
kafka-clients@3.7.1
3.9.2

Open the chart page →

9,381

Container images carrying it

121 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
bitnamilegacy/opensearch:2.18.0-debian-12-r0d8440eb6b290
kafka-clients@3.7.1
3.9.2
1
ckan/ckan-solr:2.11-solr9ef8e5d3e6be1
kafka-clients@3.9.0
3.9.2
1
conductoross/conductor:3.31.09fba127693e6
kafka-clients@3.7.2
3.9.2
1
expediagroup/pitchfork:1.314f2cf61e7de9
kafka-clients@3.0.0
3.9.2
1
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
kafka-clients@3.1.2
3.9.2
1
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
kafka-clients@3.1.2
3.9.2
1
fimperato/static-src-info-data-transformation:1.0.5-RELEASEdf05c388ea6c
kafka-clients@3.1.2
3.9.2
1
fimperato/static-src-people-detection:1.1.5-RELEASEc0cfaca070d9
kafka-clients@3.1.2
3.9.2
1
flowable/flowable-rest:7.1.0b7ae287502cd
kafka-clients@3.7.1
3.9.2
1
graviteeio/ae-engine:3.0.24140932887e0
kafka-clients@3.7.1
3.9.2
1
gresearchdev/siembol-config-editor-rest:latest91863a50afb7
kafka-clients@3.1.2
3.9.2
1
gresearchdev/siembol-storm-topology-manager:latest8dad36a05ebf
kafka-clients@3.1.2
3.9.2
1
gurolakman/smsf-configuration:1.0.49abb3882bcbd
kafka-clients@3.0.1
3.9.2
1
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
kafka-clients@3.0.1
3.9.2
1
gurolakman/smsf-momt:1.0.4ce23b20a8a17
kafka-clients@3.0.1
3.9.2
1
gurolakman/smsf-registration:1.0.4b22e746edd5d
kafka-clients@3.0.1
3.9.2
1
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
kafka-clients@3.0.1
3.9.2
1
gurolakman/ussigw-core:1.0.48739565c3ea2
kafka-clients@3.0.1
3.9.2
1
huertaslopez/i.huertas.2021-v.martinp.2021-planner:2.0.0e2c18bd65472
kafka-clients@3.0.0
3.9.2
1
hugohg34/planner:0.0.2171f61e8d7e2
kafka-clients@3.0.0
3.9.2
1
kafkace/kafka:v3.7.1-63ba8d27adc206bf5a4
kafka-clients@3.7.1
3.9.2
1
kafkakraft/kafka-connect:3.7.0062d697db7e5
kafka-clients@3.7.0
3.9.2
1
kafkakraft/kafka-controller:3.7.0f261ad288fce
kafka-clients@3.7.0
3.9.2
1
kafkakraft/kafkakraft:3.7.02e4b593b878b
kafka-clients@3.7.0
3.9.2
1
library/logstash:9.1.233eae14f0867
kafka-clients@3.9.1
3.9.2
1
lourdesmorente/new-planner:1.0.0608745878cdb
kafka-clients@3.0.0
3.9.2
1
magento/magento-cloud-docker-opensearch:2.5-1.4.059fb6f0f1461
kafka-clients@3.0.2
3.9.2
1
molynx/planner:v1441c9f52f092
kafka-clients@3.0.0
3.9.2
1
opensearchproject/logstash-oss-with-opensearch-output-plugin:8.9.043b0cdaf26ed
kafka-clients@3.3.1
3.9.2
1
opensearchproject/opensearch:2.15.01963b3ece46d
kafka-clients@3.7.0
3.9.2
1
opensearchproject/opensearch:2.14.0466a49f379bb
kafka-clients@3.7.0
3.9.2
1
opensearchproject/opensearch:3.1.0474ea3fdf25d
kafka-clients@4.0.0
4.0.2
1
opensearchproject/opensearch:2.12.0645d3d9390ad
kafka-clients@3.5.1
3.9.2
1
opensearchproject/opensearch:2.19.269588c664014
kafka-clients@3.7.1
3.9.2
1
opensearchproject/opensearch:3.3.2798cf28e226a
kafka-clients@4.0.0
4.0.2
1
opensearchproject/opensearch:2.10.0c8f3ebd2a934
kafka-clients@3.5.1
3.9.2
1
openzipkin/zipkin:2.24197a9692f6a9
kafka-clients@3.6.0
3.9.2
1
pcarrascoponce/planner:v1.0981fc482442c
kafka-clients@3.0.0
3.9.2
1
scorpiobroker/scorpio:scorpio-aaio_2.1.0db55012043df
kafka-clients@3.0.0
3.9.2
1
seataio/seata-server:latest703b5de7f1a6
kafka-clients@3.1.2
3.9.2
1
soldevelo/kafka:4.0.0-debian-12-r0cfdc08c2f577
kafka-clients@4.0.0
4.0.2
1
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
kafka-clients@3.2.0
3.9.2
1
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
kafka-clients@3.2.0
3.9.2
1
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
kafka-clients@3.2.0
3.9.2
1
thingsboard/tb-node:3.4.1645f43b688f7
kafka-clients@3.2.0
3.9.2
1
thingsboard/tb-node:3.6.0f40a542832c4
kafka-clients@3.2.0
3.9.2
1
thingsboard/tb-postgres:latest2d17e4e36edc
kafka-clients@3.9.1
3.9.2
1
traccar/traccar:6.7-alpine621c8d6d46fd
kafka-clients@4.0.0
4.0.2
1
trinodb/trino:45038c6f24ab1a4
kafka-clients@3.7.0
3.9.2
1
vitalii1992/analytics-service:latest8e798836ecea
kafka-clients@3.4.0
3.9.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.