Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 13 Jun 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 11 Jun 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dpkp
Dpkp kafka-python |
|
| CPEs | cpe:2.3:a:dpkp:kafka-python:*:*:*:*:*:python:*:* | |
| Vendors & Products |
Dpkp
Dpkp kafka-python |
Thu, 11 Jun 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 11 Jun 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Dana Powers
Dana Powers kafka-python |
|
| Vendors & Products |
Dana Powers
Dana Powers kafka-python |
Wed, 10 Jun 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by sending a crafted 4-byte frame length value without bounds validation. Attackers can send a specially crafted frame length through the receive_bytes() function to trigger either a multi-gigabyte memory allocation or an uncaught ValueError that leaves the connection in a broken state, causing requests to hang and consumers to stop heartbeating until restart. | |
| Title | kafka-python prior to 2.3.2 Denial of Service via Protocol Parser Frame Length | |
| Weaknesses | CWE-789 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-23T16:13:42.149Z
Reserved: 2026-05-29T21:38:32.287Z
Link: CVE-2026-10142
Updated: 2026-06-11T14:12:58.188Z
Status : Analyzed
Published: 2026-06-10T22:16:55.350
Modified: 2026-06-11T19:10:45.923
Link: CVE-2026-10142
OpenCVE Enrichment
Updated: 2026-06-13T02:00:08Z