Database/Control plane, storage & DevOps
Apache Kafka (client): SASL/OAUTHBEARER endpoint URLs accept file://
CVSS 7.5CVE-2025-27817Control plane, storage & DevOpscurated
Impact
SASL/OAUTHBEARER endpoint URLs accept file:// -> arbitrary file read and SSRF
Who can reach it
Network (remote)
What to do
Control-plane: client library bump across all internal producers/consumers
References
Related entries
- Apache Kafka (client): ConfigProvider plugins let an untrusted app read files/env of the Kafka client hostCVE-2024-31141 · Apache Kafka (client)Medium
- HPE Insight Remote Support (unauthenticated denial of service): An unauthenticated attacker takes Insight RS downCVE-2025-37097 · HPE Insight Remote Support (unauthenticated denial of service)High
- HPE Insight Remote Support (path traversal): Unauthenticated path traversal disclosing files from the IRS serverCVE-2025-37098 · HPE Insight Remote Support (path traversal)High
- Citrix NetScaler ADC/Gateway: "CitrixBleed 2" - insufficient input validationCVE-2025-5777 · Citrix NetScaler ADC/GatewayHigh
- Go crypto/x509 (Tailscale, Go infra): Name-constraint checking scales non-linearly with certificate sizeCVE-2025-58187 · Go crypto/x509 (Tailscale, Go infra)High
- Apache DolphinScheduler: exposed management endpoints leak database credentials to unauthenticated callersCVE-2025-62188 · Apache DolphinScheduler 3.1.x (exposed Spring Boot management endpoints)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.