Junglewise Threat Intelligence

CVE-2026-10142: dpkp kafka-python denial of service in protocol parser

CVE-2026-10142 · Severity: high · CVSS 7.5 · Published 2026-06-10

Vendors: PyPI.

Executive brief

kafka-python is a Python client library used to connect to Apache Kafka message brokers. A flaw in how it parses network protocol messages allows a malicious Kafka broker or network attacker to crash clients or make them unresponsive by sending specially crafted messages with excessive frame sizes. This can disrupt message processing applications and require manual restarts to recover.

Technical details

The vulnerability exists in the protocol frame length parsing logic within the receive_bytes() function. The vulnerable component fails to validate the 4-byte frame length field against reasonable bounds before using it to allocate memory or read data. An unauthenticated attacker with network access to a Kafka broker connection can send a crafted message with an extremely large frame length value, triggering either an uncontrolled memory allocation (leading to out-of-memory conditions) or an uncaught ValueError exception. The ValueError leaves the connection in a broken state, causing subsequent requests to hang indefinitely and heartbeat messages to stop being sent until the consumer process is manually restarted. The attack requires no authentication or user interaction. A patch is available in version 2.3.2.

Affected products

  • dpkp kafka-python < 2.3.2

Timeline

  • 2026-06-10: disclosed
  • 2026-06-11: advisory
  • 2026-06-11: patched: Version 2.3.2 released with fix

References

Related threats