VDB
CVE-2026-10143
CVE-2026-10143
PUBLISHED
CVSS 7.5 HIGH
Reported by VulnCheck · Published June 10, 2026
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the client event loop by supplying an excessively large iteration count. In scram.py, ScramClient.process_server_first_message() passes the broker-controlled SCRAM iteration count directly to hashlib.pbkdf2_hmac() without validation, blocking producer sends, consumer polls, admin operations, and heartbeats, which can cause consumer group eviction and repeated reconnect failures.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Dana Powers | kafka-python | 0 |
| Red Hat | Red Hat Quay 3.12 | 1781937357, 1781937357, 1781937357 |
| Red Hat | Red Hat Quay 3.9 | |
| dpkp | kafka-python | |
| Red Hat | Red Hat Quay 3.10 | |
| Red Hat | Red Hat Quay 3 | |
| Red Hat | Red Hat Quay 3.15 | 1784351966, 1784351966, 1784351966 |
| Red Hat | Red Hat Quay 3.16 | 1783955846, 1783955846, 1783955846 |
| Dana Powers | kafka-python | 0, 0, 0 |
| Red Hat | Red Hat Quay 3.10 | 1782487717, 1782487717, 1782487717 |
| Red Hat | Red Hat Quay 3 | |
| Red Hat | Red Hat Quay 3.1 | 1782487717, 1782487717, 1782487717 |
| Red Hat | Red Hat Quay 3.9 | 1781878070, 1781878070, 1781878070 |
| Red Hat | Red Hat Quay 3.12 |
Timeline
- Jun 10, 2026 CVE Published
- Jun 11, 2026 Coalition ESS Score
- Jun 12, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Distribution Patch
- Aug 7, 2026 Security Advisory
- Aug 7, 2026 Security Advisory
- Aug 7, 2026 Security Advisory
- Aug 17, 2026 CVE Updated
- Aug 17, 2026 Distribution Patch
References
- issue-tracking
- patch
- issue-tracking
- third-party-advisory
- https://access.redhat.com/security/cve/CVE-2026-10143 vdb
- RHBZ#2487722 issue
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10143.json url
- https://access.redhat.com/errata/RHSA-2026:30076 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:42796 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:41066 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:33683 vendor-advisory
- https://access.redhat.com/errata/RHSA-2026:28571 vendor-advisory