Red Hat Security Advisory: Streams for Apache Kafka 3.1.0 release and security update
🔗 CVE IDs covered (12)
📋 Description
CVE-2024-56128 — kafka: Apache Kafka: SCRAM authentication vulnerable to replay attacks when used without encryption CVE-2025-1634 — io.quarkus:quarkus-resteasy: Memory Leak in Quarkus RESTEasy Classic When Client Requests Timeout CVE-2025-11965 — io.vertx/vertx-core: Eclipse Vert.x Access Control Flaw CVE-2025-11966 — io.vertx/vertx-web: Eclipse Vert.x cross site scripting CVE-2025-27817 — org.apache.kafka: Kafka Client Arbitrary File Read SSRF CVE-2025-27818 — apache-kafka: Apache Kafka: Possible RCE attack via SASL JAAS LdapLoginModule configuration CVE-2025-27819 — org.apache.kafka: Kafka JNDI Login Module RCE Vulnerability CVE-2025-48924 — commons-lang/commons-lang: org.apache.commons/commons-lang3: Uncontrolled Recursion vulnerability in Apache Commons Lang CVE-2025-49574 — io.quarkus/quarkus-vertx: Quarkus potential data leak CVE-2025-55163 — netty: netty-codec-http2: Netty MadeYouReset HTTP/2 DDoS Vulnerability CVE-2025-58056 — netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions CVE-2025-58057 — netty-codec: netty-codec-compression: Netty's BrotliDecoder is vulnerable to DoS via zip bomb style attack
🎯 Affected products1
- Streams for Apache Kafka 3.1.0
✅ Remediation
Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this flaw, explicitly set the allowed urls in SASL JAAS configuration using the system property "-Dorg.apache.kafka.sasl.oauthbearer.allowed.urls". Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. Workaround: To mitigate this flaw, disable the problematic login module's usage in the SASL JAAS configuration using the system property, "-Dorg.apache.kafka.disallowed.login.modules". Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: To mitigate this issue, enforce strict RFC compliance on all front-end proxies and load balancers so that lone LF characters in chunk extensions are rejected or normalized before being forwarded. Additionally, configure input validation at the application or proxy layer to block malformed chunked requests, ensuring consistent parsing across all components in the request path.
🔗 References (15)
- selfhttps://access.redhat.com/errata/RHSA-2025:23417
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2333013
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2347319
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2371365
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2371367
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2371368
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2374376
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2379554
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2388252
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2392996
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2393000
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2405789
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2405820
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2025/rhsa-2025_23417.json