Executive brief
kafka-python is a Python client library for Apache Kafka, used to produce and consume messages from Kafka brokers. A malicious or compromised Kafka broker can freeze the client's event loop by sending an excessively large SCRAM iteration count during authentication, causing producer sends, consumer polls, and heartbeats to hang indefinitely. This can lead to consumer group eviction and application failures.
Technical details
The vulnerability exists in scram.py, specifically in ScramClient.process_server_first_message(), where the SCRAM iteration count from the broker is used directly in a pbkdf2_hmac() call without upper-bound validation. SCRAM authentication is a network-accessible operation triggered automatically during client connection; no user interaction or privileges are required. An attacker positioned as a MITM or malicious broker can inject an arbitrarily large iteration count (e.g., 2^31 or higher) causing cryptographic key derivation to block indefinitely. This blocks producer sends, consumer polls, admin operations, and heartbeats, eventually causing consumer group eviction and cascading reconnection failures. The fix validates the iteration count before passing it to pbkdf2_hmac(). Version 2.3.2 and later contain the fix.
Affected products
- dpkp kafka-python < 2.3.2
Timeline
- 2026-06-10: disclosed
- 2026-06-11: advisory
- 2026-06-11: patched: Version 2.3.2 released