CVE-2026-15911
7.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Summary
Confluent Kafka Python client's HashiCorp Vault KMS integration could allow a remote attacker to obtain sensitive information due to improper TLS certificate validation.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| confluent | confluent-kafka | 0 <= 2.14.2 | affected |
Weaknesses
- CWE-295: CWE-295 Improper certificate validation
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.