StackRadar

CVE-2026-35554

High

Advisory

Published 7 Apr 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
127
of 17,781 indexed, latest versions
Container images
121
deployed by those charts
Fix available
1 of 1
affected package

Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition

Carried by container images the latest versions of 127 of 17,781 indexed charts deploy, on 121 images.

Affected packageAffected versionsFixed inImages
kafka-clientsmaven2.8.1, 2.8.2, 3.0.0, 3.0.1+21 more3.9.2, 4.0.2, 4.1.2121
OSV records
GHSA-5qcv-4rpc-jp93

Charts affected

127 by stars
ChartLatestAffected imagesRadar Score
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
kafka-clients@3.8.1
3.9.2

Open the chart page →

7,792
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,607
smsf-dispatcheropenshift1.0.41 of 1See more

smsf-dispatcher openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/smsf-dispatcher:1.0.46537e8ed8de8
kafka-clients@3.0.1
3.9.2

Open the chart page →

11,738
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
kafka-clients@3.0.1
3.9.2

Open the chart page →

13,100
dfdeweyosdfir-infrastructureVerified publisher1.0.01 of 3See more

dfdewey osdfir-infrastructure 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.12.0645d3d9390ad
kafka-clients@3.5.1
3.9.2

Open the chart page →

1,190
osdfir-infrastructureosdfir-infrastructureVerified publisher2.15.01 of 40See more

osdfir-infrastructure osdfir-infrastructure 2.15.0

1 of the 40 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:3.1.0474ea3fdf25d
kafka-clients@4.0.0
4.0.2

Open the chart page →

71,208
timesketchosdfir-infrastructureVerified publisher1.0.81 of 6See more

timesketch osdfir-infrastructure 1.0.8

1 of the 6 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.14.0466a49f379bb
kafka-clients@3.7.0
3.9.2

Open the chart page →

1,753
p4p40.1.01 of 7See more

p4 p4 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
mastercloudapps/planner:v1.2340a950b311b2
kafka-clients@3.0.0
3.9.2

Open the chart page →

27,537
Practica_4_helmpr04helm0.1.01 of 7See more

Practica_4_helm pr04helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
pcarrascoponce/planner:v1.0981fc482442c
kafka-clients@3.0.0
3.9.2

Open the chart page →

27,558
rada-platformrada-platform0.1.01 of 7See more

rada-platform rada-platform 0.1.0

1 of the 7 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
trinodb/trino:45038c6f24ab1a4
kafka-clients@3.7.0
3.9.2

Open the chart page →

21,211
radar-kafkaradar-baseVerified publisher0.4.11 of 2See more

radar-kafka radar-base 0.4.1

1 of the 2 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
kafka-clients@4.0.0
4.0.2

Open the chart page →

4,219
strimzi-kafka-operatorradar-baseVerified publisher0.46.01 of 1See more

strimzi-kafka-operator radar-base 0.46.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.46.0ac434a48ac2b
kafka-clients@4.0.0
4.0.2

Open the chart page →

1,951
kafkasb-helm-charts0.3.01 of 2See more

kafka sb-helm-charts 0.3.0

1 of the 2 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
provectuslabs/kafka-ui:latest8f2ff02d64b0
kafka-clients@3.5.0
3.9.2

Open the chart page →

1,597
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
kafka-clients@3.1.2
3.9.2

Open the chart page →

4,245
shenyushenyu0.6.31 of 2See more

shenyu shenyu 0.6.3

1 of the 2 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
apache/shenyu-bootstrap:2.5.11bd5756f6273
kafka-clients@3.0.1
3.9.2

Open the chart page →

8,804
strimzi-user-operatorspartan0.4.01 of 1See more

strimzi-user-operator spartan 0.4.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
quay.io/strimzi/operator:0.45.158c727cd2e68
kafka-clients@3.9.1
3.9.2

Open the chart page →

1,836
static-src-people-detector-appstatic-src-people-detector-chartVerified publisher1.5.54 of 6See more

static-src-people-detector-app static-src-people-detector-chart 1.5.5

4 of the 6 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
fimperato/detected-info-notification:1.2.6-RELEASE6441f6545613
kafka-clients@3.1.2
3.9.2
fimperato/detected-info-store:1.1.0-RELEASEe32920eedd3a
kafka-clients@3.1.2
3.9.2
fimperato/static-src-info-data-transformation:1.0.5-RELEASEdf05c388ea6c
kafka-clients@3.1.2
3.9.2
fimperato/static-src-people-detection:1.1.5-RELEASEc0cfaca070d9
kafka-clients@3.1.2
3.9.2

Open the chart page →

13,646
netforge-besvtechVerified publisher0.0.21 of 3See more

netforge-be svtech 0.0.2

1 of the 3 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
conductoross/conductor:3.31.09fba127693e6
kafka-clients@3.7.2
3.9.2

Open the chart page →

4,674
hadoop-deploymenttejaswita-hadoop-helmchart1.0.01 of 1See more

hadoop-deployment tejaswita-hadoop-helmchart 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
apache/hadoop:3af361b20bec0
kafka-clients@2.8.2
3.9.2

Open the chart page →

4,240
thingsboardthingsboardVerified publisher0.1.34 of 12See more

thingsboard thingsboard 0.1.3

4 of the 12 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
thingsboard/tb-coap-transport:3.4.1bd45a09d85d9
kafka-clients@3.2.0
3.9.2
thingsboard/tb-http-transport:3.4.1a06f53c5e2da
kafka-clients@3.2.0
3.9.2
thingsboard/tb-mqtt-transport:3.4.1030f316ce301
kafka-clients@3.2.0
3.9.2
thingsboard/tb-node:3.4.1645f43b688f7
kafka-clients@3.2.0
3.9.2

Open the chart page →

25,394
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
kafka-clients@3.7.1
3.9.2

Open the chart page →

2,144
wazuhwazuh-helm-eksVerified publisher1.2.101 of 6See more

wazuh wazuh-helm-eks 1.2.10

1 of the 6 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
wazuh/wazuh-indexer:4.14.49c344d2b1757
kafka-clients@3.9.1
3.9.2

Open the chart page →

5,484
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
kafka-clients@2.8.2
3.9.2

Open the chart page →

9,397
ygdrassil-monitoringygdrassilVerified publisher0.4.01 of 10See more

ygdrassil-monitoring ygdrassil 0.4.0

1 of the 10 container images this version deploys carry CVE-2026-35554.

Container imageDigestPackageFixed in
opensearchproject/opensearch:2.18.07f6fa1efee8f
kafka-clients@3.7.1
3.9.2

Open the chart page →

9,381

Container images carrying it

121 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
wurstmeister/kafka:latest2d4bbf9cc83d
kafka-clients@2.8.1
3.9.2
7
solsson/kafka:latest41e5d8f6f290
kafka-clients@3.3.0
3.9.2
5
mastercloudapps/planner:v1.2340a950b311b2
kafka-clients@3.0.0
3.9.2
4
quay.io/strimzi/operator:0.37.052f376e64b9b
kafka-clients@3.5.1
3.9.2
4
codeurjc/planner:v1.0800cf520c245
kafka-clients@3.0.0
3.9.2
3
provectuslabs/kafka-ui:latest8f2ff02d64b0
kafka-clients@3.5.0
3.9.2
3
apache/druid:37.0.00116fb802786
kafka-clients@3.9.1
3.9.2
2
apache/fineract:1.12.1a83cf1980609
kafka-clients@3.8.1
3.9.2
2
dina1993/airports-api:latestac731244aed1
kafka-clients@3.3.2
3.9.2
2
dina1993/airports-consumer:latest669d146a5e63
kafka-clients@3.3.2
3.9.2
2
dina1993/airports-producer:latest3d6b0dac1cb4
kafka-clients@3.3.2
3.9.2
2
graviteeio/apim-gateway:4.12.19-debian05fd67a93056
kafka-clients@3.7.1
3.9.2
2
graviteeio/apim-management-api:4.12.19-debian27374522cd04
kafka-clients@3.7.1
3.9.2
2
obsidiandynamics/kafdrop:3.30.05337c9e0e2de
kafka-clients@3.0.1
3.9.2
2
opensearchproject/opensearch:2.1.04254021a8c71
kafka-clients@3.0.1
3.9.2
2
opensearchproject/opensearch:2.18.07f6fa1efee8f
kafka-clients@3.7.1
3.9.2
2
scorpiobroker/scorpio:RegistrySubscriptionManager_2.1.001e11d800459
kafka-clients@3.0.0
3.9.2
2
scorpiobroker/scorpio:eureka-server_2.1.03f05a113a4be
kafka-clients@3.0.0
3.9.2
2
scorpiobroker/scorpio:AtContextServer_2.1.05073ceef2fa0
kafka-clients@3.0.0
3.9.2
2
scorpiobroker/scorpio:gateway_2.1.062dae3dd0eeb
kafka-clients@3.0.0
3.9.2
2
scorpiobroker/scorpio:RegistryManager_2.1.0a2cfcf0947fd
kafka-clients@3.0.0
3.9.2
2
scorpiobroker/scorpio:QueryManager_2.1.0b742a53b2803
kafka-clients@3.0.0
3.9.2
2
scorpiobroker/scorpio:HistoryManager_2.1.0b7fe27a06ff5
kafka-clients@3.0.0
3.9.2
2
scorpiobroker/scorpio:SubscriptionManager_2.1.0e08036670d66
kafka-clients@3.0.0
3.9.2
2
scorpiobroker/scorpio:EntityManager_2.1.0f02e8a429a08
kafka-clients@3.0.0
3.9.2
2
quay.io/keycloak/keycloak:17.0.1-legacy68f9f38c8f30
kafka-clients@3.0.0
3.9.2
2
quay.io/strimzi/operator:0.39.002f6f143fc6d
kafka-clients@3.6.1
3.9.2
2
quay.io/strimzi/operator:0.46.0ac434a48ac2b
kafka-clients@4.0.0
4.0.2
2
2martens/configserver:latestbf1cdb80239d
kafka-clients@3.7.1
3.9.2
1
5200710/hive:3.1.3-postgresql-metastoree34ab066d2ed
kafka-clients@2.8.1
3.9.2
1
adagber/planner:v1.0e5c1ed097752
kafka-clients@3.0.0
3.9.2
1
aktosecurity/data-ingestion-service213aded7adc5
kafka-clients@3.9.1
3.9.2
1
aktosecurity/data-ingestion-service:1.4.946ed5bcb04b2
kafka-clients@3.9.1
3.9.2
1
andrianrf/backoffice-be:latest6036614803d4
kafka-clients@3.1.2
3.9.2
1
apache/drill:1.21.11f96558fd292
kafka-clients@2.8.2
3.9.2
1
apache/druid:29.0.10cef139b6bf1
kafka-clients@3.6.1
3.9.2
1
apache/hadoop:3af361b20bec0
kafka-clients@2.8.2
3.9.2
1
apache/hertzbeat:1.8.075d48a62748f
kafka-clients@3.7.1
3.9.2
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
kafka-clients@3.7.1
3.9.2
1
apache/kafka:4.1.0bff074a5d005
kafka-clients@4.1.0
4.1.2
1
apache/kafka:3.9.0fbc7d7c428e3
kafka-clients@3.9.0
3.9.2
1
apache/shenyu-bootstrap:2.5.11bd5756f6273
kafka-clients@3.0.1
3.9.2
1
apicurio/apicurio-studio-api:0.2.62.Final302d202ed149
kafka-clients@3.3.2
3.9.2
1
apicurio/apicurio-studio-ws:0.2.62.Final27a91978a388
kafka-clients@3.3.2
3.9.2
1
arturisimo/planner:v1.0fff9de644941
kafka-clients@3.0.0
3.9.2
1
assistiot/automated_configuration:latest23f195a7a26a
kafka-clients@2.8.1
3.9.2
1
assistiot/identity-manager_kc:latest0df4b4fa899a
kafka-clients@3.1.0
3.9.2
1
bitnamilegacy/kafka:3.5.0-debian-11-r08657bb93a581
kafka-clients@3.5.0
3.9.2
1
bitnamilegacy/kafka:3.4.0-debian-11-r6ac64829e45b3
kafka-clients@3.4.0
3.9.2
1
bitnamilegacy/kafka:2.8.1-debian-11-r7b6e381ffd6ae
kafka-clients@2.8.1
3.9.2
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.