#1139878 python-kafka: CVE-2026-10142

Package:
src:python-kafka
Source:
src:python-kafka
Submitter:
Moritz Mühlenhoff
Date:
2026-09-17 22:23:02 UTC
Severity:
normal
Tags:
#1139878#5
Date:
2026-06-12 22:36:40 UTC
From:
To:
Hi,

The following vulnerability was published for python-kafka.

CVE-2026-10142[0]:
| kafka-python prior to 2.3.2 contains a denial-of-service
| vulnerability in the protocol parser that allows a malicious broker
| or machine-in-the-middle attacker to exhaust memory or hang
| connections by sending a crafted 4-byte frame length value without
| bounds validation. Attackers can send a specially crafted frame
| length through the receive_bytes() function to trigger either a
| multi-gigabyte memory allocation or an uncaught ValueError that
| leaves the connection in a broken state, causing requests to hang
| and consumers to stop heartbeating until restart.

https://github.com/dpkp/kafka-python/pull/3019
https://github.com/dpkp/kafka-python/pull/3026
Fixed by: https://github.com/dpkp/kafka-python/commit/6e4831444f972d169cdd11f5c8d50333cea3f19b (3.0.0)


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-10142
https://www.cve.org/CVERecord?id=CVE-2026-10142

Please adjust the affected versions in the BTS as needed.

#1139878#10
Date:
2026-06-13 14:26:47 UTC
From:
To:
Hello,

Bug #1139878 in python-kafka reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/python/python-kafka/-/commit/3b98ca86867701e9dddf40d33ca4d4bc2869d45f
------------------------------------------------------------------------
* CVE-2026-10142 CVE-2026-10143: kafka-python contains a denial-of-service
    vulnerability in the protocol parser that allows a malicious broker or
    machine-in-the-middle attacker to exhaust memory or hang connections by
    sending a crafted 4-byte frame length value without bounds validation.
    Attackers can send a specially crafted frame length through the
    receive_bytes() function to trigger either a multi-gigabyte memory
    allocation or an uncaught ValueError that leaves the connection in a broken
    state, causing requests to hang and consumers to stop heartbeating until
    restart. Applied upstream patch: "Validate SASL/SCRAM iterations".
    (Closes: #1139878, #1139822).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1139878

#1139878#17
Date:
2026-06-13 15:04:25 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python-kafka, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1139878@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated python-kafka package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 13 Jun 2026 16:14:41 +0200
Source: python-kafka
Architecture: source
Version: 2.0.2-12
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1139822 1139878
Changes:
 python-kafka (2.0.2-12) unstable; urgency=medium
 .
   * CVE-2026-10142 CVE-2026-10143: kafka-python contains a denial-of-service
     vulnerability in the protocol parser that allows a malicious broker or
     machine-in-the-middle attacker to exhaust memory or hang connections by
     sending a crafted 4-byte frame length value without bounds validation.
     Attackers can send a specially crafted frame length through the
     receive_bytes() function to trigger either a multi-gigabyte memory
     allocation or an uncaught ValueError that leaves the connection in a broken
     state, causing requests to hang and consumers to stop heartbeating until
     restart. Applied upstream patch: "Validate SASL/SCRAM iterations".
     (Closes: #1139878, #1139822).
Checksums-Sha1:
 5b9349ba28d2494a8822b22d85330ddb8d0d1803 2299 python-kafka_2.0.2-12.dsc
 e1086f767263824c1991ac678fbe5193c14422a6 11276 python-kafka_2.0.2-12.debian.tar.xz
 00539bdd4a7e0dfcd2e1c88b17542f1db725f74e 8877 python-kafka_2.0.2-12_amd64.buildinfo
Checksums-Sha256:
 fd521e7f29eb9d32f65aaf802202ac90baec07dcf24d8a83df39c09d9e3c81b2 2299 python-kafka_2.0.2-12.dsc
 772800ce1dbb107e368c2d580e78f4c7f04e38c25dccdcea7a62ff663ea45ec6 11276 python-kafka_2.0.2-12.debian.tar.xz
 efbe00c389f78ca6f10aa7444a3e7ec5d4e8644a7c3cb0107ba6417b5a7983d3 8877 python-kafka_2.0.2-12_amd64.buildinfo
Files:
 b6c99144d03f0d07f6f5418a54993b31 2299 python optional python-kafka_2.0.2-12.dsc
 9db2c7a891cc2569002dbd013c284609 11276 python optional python-kafka_2.0.2-12.debian.tar.xz
 8b65c351b853a9187ab6e6b39a52d160 8877 python optional python-kafka_2.0.2-12_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmotaK4ACgkQ1BatFaxr
Q/6eQA/+KUNvf6VVyPCBId0HwKjmrVYUbtg5d0ZUVWIm9fPO8UxcViDzwCXY4LDl
56Bb6jraWmE19fSza/DqBAsRQuXbdPl+ULxzhBiu5eQqZza+0jBT/HAnVPSL9yzf
pA9r+oEiZXCxP5sw7uCSDpiDwdfpfgI1iVAUD7vBF40JYEA00lPb9HbUoTpg8bdY
zoAdyWvCFRRpOxydxiA2QnBkQ59Fa/pocQgzOnWAmXtMQp+1NWQB2oJcnLOovIY/
Su8roojWqOxm3FBadQu5Oq9Ijj1x+/foSfAUyCsF2eWnMFoxmOg9pPtexFTn87HJ
F6M7NLnQkTcOl5f1OQyjsH/mt6i/qArcFRTzc/FNKPAZZ9cEfHzvOHYRxkOtQUPT
NTd2tltpY8iG7XluKZhy9Z9znNjqMevPYklY4Xodt/QdjU9P0ivfbZe2Y2rMwrrG
QKDgLS2IO9vT1/0YGglkar/zAc3iM4UItyf40MHKL02A7fuJne3l318XiR7qwXz3
mykjzH+VmaiJvbDq2yF7MX/b9aJVGoJN6hbq4oY+Hh4qxWZZ+RfcgQTTAt9Guqcp
K/mmkkSwt/VUqvYy8DS33aC/ra1HxOVa/GT0klU0Z2ygrRd0ZJ687hVF/18ukSGc
YA5y4eIP8D2tVEWK/sH2O1st1TwTW30latWXE3qWXWfjzUkaBE8=
=QUyg
-----END PGP SIGNATURE-----

#1139878#22
Date:
2026-06-23 15:33:57 UTC
From:
To:
 python-kafka (2.0.2-12) unstable; urgency=medium
 .
   * CVE-2026-10142 CVE-2026-10143: kafka-python contains a denial-of-service
     vulnerability in the protocol parser that allows a malicious broker or
     machine-in-the-middle attacker to exhaust memory or hang connections by
     sending a crafted 4-byte frame length value without bounds validation.
     Attackers can send a specially crafted frame length through the
     receive_bytes() function to trigger either a multi-gigabyte memory
     allocation or an uncaught ValueError that leaves the connection in a broken
     state, causing requests to hang and consumers to stop heartbeating until
     restart. Applied upstream patch: "Validate SASL/SCRAM iterations".
     (Closes: #1139878, #1139822).

This is the fix for CVE-2026-10143.
https://github.com/dpkp/kafka-python/commit/bdb46ab1fe4f090dd8bf710c7ddb778993bbc16b

Upstream additionally lists as needed for the CVEs:
https://github.com/dpkp/kafka-python/commit/7250337f54ee60695f2a7faedd1ec2758fc7ac29

Further details:
https://github.com/dpkp/kafka-python/issues/3014#issuecomment-4663299889

cu
Adrian

#1139878#29
Date:
2026-09-17 15:32:19 UTC
From:
To:
Hello,

Bug #1139878 in python-kafka reported by you has been fixed in the
Git repository and is awaiting an upload. You can see the commit
message below and you can check the diff of the fix at:

https://salsa.debian.org/openstack-team/python/python-kafka/-/commit/590ca2fcf83c37685c9ab67df6ae7f6c87ceea12
* CVE-2026-10142: the last Debian version didn't fully address the issue.
  Applied upstream patch: "KafkaProtocol: validate network frame size",
  backported to the legacy kafka.conn architecture of this release,
  including the accompanying unit tests.
  (Closes: #1139878).
------------------------------------------------------------------------

(this message was generated automatically)
-- 
Greetings

https://bugs.debian.org/1139878

#1139878#36
Date:
2026-09-17 22:20:54 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
python-kafka, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1139878@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Thomas Goirand <zigo@debian.org> (supplier of updated python-kafka package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Thu, 17 Sep 2026 17:48:52 +0200
Source: python-kafka
Architecture: source
Version: 2.0.2-13
Distribution: unstable
Urgency: medium
Maintainer: Debian OpenStack <team+openstack@tracker.debian.org>
Changed-By: Thomas Goirand <zigo@debian.org>
Closes: 1139878
Changes:
 python-kafka (2.0.2-13) unstable; urgency=medium
 .
   * CVE-2026-10142: the last Debian version didn't fully address the issue.
     Applied upstream patch: "KafkaProtocol: validate network frame size",
     backported to the legacy kafka.conn architecture of this release,
     including the accompanying unit tests.
     (Closes: #1139878).
Checksums-Sha1:
 2a83311020dd14e78e0940b932b0da6bbd8b1ec7 2299 python-kafka_2.0.2-13.dsc
 eab10dcff420d692f646edada1c081472f69bca1 13544 python-kafka_2.0.2-13.debian.tar.xz
 53878c1bdd5e65f20447109610080b4b5c9293fb 8434 python-kafka_2.0.2-13_amd64.buildinfo
Checksums-Sha256:
 0fb42ad31e57ed82c50ecd248bcc8dd717d486c64b493aa54f2fe9f6c1a4b956 2299 python-kafka_2.0.2-13.dsc
 a52686c622e7699c378067391037e1bcedcb93d7c3bae8be0efb4e308ef0c375 13544 python-kafka_2.0.2-13.debian.tar.xz
 34f912c3e8c36e7403d733b30891af1a099e0be4fed84052107810b56abe3341 8434 python-kafka_2.0.2-13_amd64.buildinfo
Files:
 27dc0c6d2f87ff7b458aba19145805dc 2299 python optional python-kafka_2.0.2-13.dsc
 ca473cbbcb73384ef5b06292e86fd7e4 13544 python optional python-kafka_2.0.2-13.debian.tar.xz
 1281c019d1067058936c4205d10db3be 8434 python optional python-kafka_2.0.2-13_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEoLGp81CJVhMOekJc1BatFaxrQ/4FAmqsZQAACgkQ1BatFaxr
Q/7mDg//Wj5ktme0mYLDGBUEZ3nzhDI4YcEpdS4RgHG2zsIVm2qCGhba4eRtsVvA
tn5c4js0oWKmaCXWSZlLaxkZiH4HWtZTeRQHywuDjflh87hwlTJUx+zL9QclfovM
1aGvB5hMUxRKK89gDKf/3dQFEiS8+lACLz4NI596eRReY3Z3c2PMMYVyUo7/CeAr
8lTX5iGUyE82byUNHYNmTKdO7qaVjHxQ5siBq6vs/jf8CgZ0IiaPo4frj7pIykD5
g6jT6yP/oxz2qMGLLvAriP7lR1NF86EoYQ/EVxkLzvmqgcUtvbqFXbgUoyhxXQnl
oAiJH6WjDGmSGkYILie6EZCINB31HhAPH7PiidoxrWv7Vk+TCfoopj5bC1sa1rjh
exB6iIgQe/ystCu1rd5TtsyGT37K6muGaoyJqngtgFCOnX5nQyfl/D3VZ0PNP2NB
6YNx43F16Lz9/biH14lH0iLwkiZkkayzUakDU2UeXtk6oZpPUkahnzhgu1MHRSsj
QPFbihm6rGdn/mXrX0EBaXueHXixUMLbnnClFS6TFv+8VRRpZ/b+hz04V/l7o1Cz
LA486jANuEJrm07E46H+FYdCGY9TujQq2oWM17IqwynnRrKGp6d7e+7IWxrRZzEx
wUU/Tr0nM/Avl5OP+ZG94ZBXqGc+4Dt4ysYnHguukG85ZOGW0ps=
=bDoh
-----END PGP SIGNATURE-----