{"api_version":"v1","generated_at":"2026-10-06T19:00:00+00:00","product":{"cve_count":11,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-kafka-31fa36a5a9bb","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Kafka","next_cursor":null,"observations":[{"affected":"4.0.0 \u2264 4.3.0","affected_versions_present":true,"cve_id":"CVE-2026-41115","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-41115","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-06-02T17:33:07.625Z","patch_url":"","primary_source":"","published":"2026-06-02T08:56:43.636Z"},{"affected":"4.1.0 \u2264 4.1.1","affected_versions_present":true,"cve_id":"CVE-2026-33557","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33557","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-07-15T01:06:14.162Z","patch_url":"https://lists.apache.org/thread/v57o00hm6yszdpdnvqx2ss4561yh953h","primary_source":"","published":"2026-04-20T13:28:43.669Z"},{"affected":"0.11.0 \u2264 3.9.1; 4.0.0","affected_versions_present":true,"cve_id":"CVE-2026-33558","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-33558","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-04-20T14:20:41.640Z","patch_url":"https://lists.apache.org/thread/pz5g4ky3h0k91tfd14p0dzqjp80960kl","primary_source":"","published":"2026-04-20T13:20:38.059Z"},{"affected":"2.0.0 \u2264 3.3.2","affected_versions_present":true,"cve_id":"CVE-2025-27819","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27819","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-06-10T15:15:58.031Z","patch_url":"","primary_source":"","published":"2025-06-10T07:54:41.896Z"},{"affected":"2.3.0 \u2264 3.9.0","affected_versions_present":true,"cve_id":"CVE-2025-27818","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27818","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-26T17:51:05.352Z","patch_url":"","primary_source":"","published":"2025-06-10T07:52:31.778Z"},{"affected":"0.10.2.0 < 3.7.2; 3.8.0","affected_versions_present":true,"cve_id":"CVE-2024-56128","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-56128","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-12-18T17:02:47.926Z","patch_url":"","primary_source":"","published":"2024-12-18T13:38:03.068Z"},{"affected":"3.5.0 \u2264 3.5.2; 3.6.0 \u2264 3.6.1","affected_versions_present":true,"cve_id":"CVE-2024-27309","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-27309","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-07-30T03:55:45.408Z","patch_url":"","primary_source":"","published":"2024-04-12T06:58:45.134Z"},{"affected":"Apache Kafka 2.8.0 2.8.0 ; Apache Kafka 2.8.1 2.8.1; Apache Kafka 3.0.0 3.0.0; Apache Kafka 3.0.1 3.0.1; Apache Kafka 3.1.0 3.1.0; Apache Kafka 3.1.1 3.1.1; Apache Kafka 3.2.0 3.2.0; Apache Kafka 3.2.1 3.2.1","affected_versions_present":true,"cve_id":"CVE-2022-34917","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-34917","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-05-29T13:39:10.405Z","patch_url":"","primary_source":"","published":"2022-09-20T08:35:07.000Z"},{"affected":"Apache Kafka 2.0.x \u2264 2.0.1; Apache Kafka 2.1.x \u2264 2.1.1; Apache Kafka 2.2.x \u2264 2.2.2; Apache Kafka 2.3.x \u2264 2.3.1; Apache Kafka 2.4.x \u2264 2.4.1; Apache Kafka 2.5.x \u2264 2.5.1; Apache Kafka 2.6.x \u2264 2.6.2; Apache Kafka 2.7.x \u2264 2.7.1","affected_versions_present":true,"cve_id":"CVE-2021-38153","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-38153","fixed":"Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258","last_modified":"2024-08-04T01:37:15.929Z","patch_url":"https://access.redhat.com/security/cve/CVE-2021-38153","primary_source":"","published":"2021-09-22T09:05:11.000Z"},{"affected":"0.9.0.0 to 0.9.0.1; 0.10.0.0 to 0.10.2.1; 0.11.0.0 to 0.11.0.2; 1.0.0","affected_versions_present":true,"cve_id":"CVE-2018-1288","cve_url":"https://cve.blacktree.nl/cve/CVE-2018-1288","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2024-09-17T02:52:05.951Z","patch_url":"https://www.oracle.com/security-alerts/cpujul2020.html","primary_source":"","published":"2018-07-26T14:00:00.000Z"},{"affected":"0.10.0.0 to 0.10.2.1; 0.11.0.0 to 0.11.0.1","affected_versions_present":true,"cve_id":"CVE-2017-12610","cve_url":"https://cve.blacktree.nl/cve/CVE-2017-12610","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T01:10:36.261Z","patch_url":"","primary_source":"","published":"2018-07-26T14:00:00.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Apache Software Foundation"}}
