Executive brief
kafka-python is a Python client library used to connect to Apache Kafka message brokers. A flaw in how it parses network protocol messages allows a malicious Kafka broker or network attacker to crash clients or make them unresponsive by sending specially crafted messages with excessive frame sizes. This can disrupt message processing applications and require manual restarts to recover.
Technical details
The vulnerability exists in the protocol frame length parsing logic within the receive_bytes() function. The vulnerable component fails to validate the 4-byte frame length field against reasonable bounds before using it to allocate memory or read data. An unauthenticated attacker with network access to a Kafka broker connection can send a crafted message with an extremely large frame length value, triggering either an uncontrolled memory allocation (leading to out-of-memory conditions) or an uncaught ValueError exception. The ValueError leaves the connection in a broken state, causing subsequent requests to hang indefinitely and heartbeat messages to stop being sent until the consumer process is manually restarted. The attack requires no authentication or user interaction. A patch is available in version 2.3.2.
Affected products
- dpkp kafka-python < 2.3.2
Timeline
- 2026-06-10: disclosed
- 2026-06-11: advisory
- 2026-06-11: patched: Version 2.3.2 released with fix