StackRadar

CVE-2026-35554

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
127
of 17,781 indexed, latest versions
Container images
121
deployed by those charts
Fix available
1 of 1
affected package

Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition

Carried by container images the latest versions of 127 of 17,781 indexed charts deploy, on 121 images.

Affected packageAffected versionsFixed inImages
kafka-clientsmaven2.8.1, 2.8.2, 3.0.0, 3.0.1+21 more3.9.2, 4.0.2, 4.1.2121
OSV records
GHSA-5qcv-4rpc-jp93

Charts affected

127 by stars
ChartLatestAffected imagesRadar Score
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
kafka-clients@3.8.1
3.9.2

Open the chart page →

7,792
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
kafka-clients@3.0.1
3.9.2

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,100
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
kafka-clients@3.5.1
3.9.2

Open the chart page →

1,190
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
kafka-clients@4.0.0
4.0.2

Open the chart page →

71,208
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
kafka-clients@3.7.0
3.9.2

Open the chart page →

1,753
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
kafka-clients@3.0.0
3.9.2

Open the chart page →

27,537
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
pcarrascoponce/planner:v1.0981fc482442c
kafka-clients@3.0.0
3.9.2

Open the chart page →

27,558
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
kafka-clients@3.7.0
3.9.2

Open the chart page →

21,211
radar-kafkaradar-baseVerified publisher0.4.11 of 2See more

radar-kafka radar-base 0.4.1

1 of the 2 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
kafka-clients@4.0.0
4.0.2

Open the chart page →

4,219
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
kafka-clients@4.0.0
4.0.2

Open the chart page →

1,951
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
kafka-clients@3.5.0
3.9.2

Open the chart page →

1,597
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
kafka-clients@3.1.2
3.9.2

Open the chart page →

4,245
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
kafka-clients@3.0.1
3.9.2

Open the chart page →

8,804
strimzi-user-operatorspartan0.4.01 of 1See more

strimzi-user-operator spartan 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.45.158c727cd2e68
kafka-clients@3.9.1
3.9.2

Open the chart page →

1,836
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.54 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

4 of the 6 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
kafka-clients@3.1.2
3.9.2
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
kafka-clients@3.1.2
3.9.2
fimperato/static-src-info-data-transformation:1.0.5-RELEASEdf05c388ea6c
kafka-clients@3.1.2
3.9.2
fimperato/static-src-people-detection:1.1.5-RELEASEc0cfaca070d9
kafka-clients@3.1.2
3.9.2

Open the chart page →

13,646
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
kafka-clients@3.7.2
3.9.2

Open the chart page →

4,674
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
kafka-clients@2.8.2
3.9.2

Open the chart page →

4,240
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
kafka-clients@3.2.0
3.9.2
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
kafka-clients@3.2.0
3.9.2
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
kafka-clients@3.2.0
3.9.2
thingsboard/tb-node:3.4.1645f43b688f7
kafka-clients@3.2.0
3.9.2

Open the chart page →

25,394
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
kafka-clients@3.7.1
3.9.2

Open the chart page →

2,144
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
kafka-clients@3.9.1
3.9.2

Open the chart page →

5,484
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
kafka-clients@2.8.2
3.9.2

Open the chart page →

9,397
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
kafka-clients@3.7.1
3.9.2

Open the chart page →

9,381

Container images carrying it

121 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
vitalii1992/quotes-provider-service:latest44d2d6e00ab3
kafka-clients@3.4.0
3.9.2
1
vlebediantsev/logic-ms:latestdf8bf38c535b
kafka-clients@3.1.1
3.9.2
1
vlebediantsev/registration-ms-final:latest427af418b75e
kafka-clients@3.1.1
3.9.2
1
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
kafka-clients@3.1.1
3.9.2
1
wazuh/wazuh-indexer:4.14.49c344d2b1757
kafka-clients@3.9.1
3.9.2
1
wazuh/wazuh-indexer:4.11.1a7a2076b167e
kafka-clients@3.7.1
3.9.2
1
wazuh/wazuh-indexer:4.14.3b149b30da686
kafka-clients@3.9.1
3.9.2
1
xeotek/kadeck:4.2.94c6b04d9ce55
kafka-clients@3.3.1
3.9.2
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
kafka-clients@3.6.1
3.9.2
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
kafka-clients@3.3.2
3.9.2
1
ghcr.io/devops-ia/kafka-cruise-control:jdk17-cc2.5.146-iam2.3.8e310642de2e2
kafka-clients@4.0.0
4.0.2
1
ghcr.io/fleeksoft/hbase/hdfs:3.3.3.2ac62269785ac
kafka-clients@2.8.1
3.9.2
1
ghcr.io/kubelauncher/kafka43e1085cd0a8
kafka-clients@3.9.0
3.9.2
1
ghcr.io/melodyyangaws/hive-metastore:3.0.0e949b0f733f0
kafka-clients@2.8.1
3.9.2
1
ghcr.io/open-telemetry/demo:1.12.0-kafka071a788162e8
kafka-clients@3.7.0
3.9.2
1
public.ecr.aws/aktosecurity/akto-api-security-testing-db-layer:1.59.3_local8cdcb7e83f9f
kafka-clients@3.7.2
3.9.2
1
public.ecr.aws/v0r6c2e2/hive-metastore:latest794b3bff9510
kafka-clients@2.8.2
3.9.2
1
quay.io/apicurio/apicurio-registry-mem:2.5.8.Final3b036692d546
kafka-clients@3.5.1
3.9.2
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
kafka-clients@3.3.2
3.9.2
1
quay.io/strimzi/operator:0.45.158c727cd2e68
kafka-clients@3.9.1
3.9.2
1
quay.io/strimzi/operator:0.36.1e9e03b31007c
kafka-clients@3.5.1
3.9.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.