Issued:
2026-07-02
Updated:
2026-07-02

RHSA-2026:34608 - Important: Streams for Apache Kafka 2.9.4 release and security update


Synopsis

Important: Streams for Apache Kafka 2.9.4 release and security update

Type/Severity

Security Advisory Important

Topic

Streams for Apache Kafka 2.9.4 is now available from the Red Hat Customer Portal.

Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section.

Description

Red Hat Streams for Apache Kafka, based on the Apache Kafka project, offers a distributed backbone that allows microservices and other applications to share data with extremely high throughput and extremely low latency.

This release of Red Hat Streams for Apache Kafka 2.9.4 serves as a replacement for Red Hat Streams for Apache Kafka 2.9.3, and includes security and bug fixes, and enhancements.

Security Fix(es):

  • jose4j: Denial of Service via compressed JWE content (CVE-2024-29371)
  • cluster-operator: Cross-namespace privilege escalation via Kafka.spec.entityOperator.watchedNamespace in Strimzi (CVE-2026-55225)
  • netty-codec-http: Netty is vulnerable to request smuggling due to incorrect parsing of chunk extensions (CVE-2025-58056)
  • lodash: Arbitrary code execution via untrusted input in template imports (CVE-2026-4800)
  • React Server Components: Denial of Service via specially crafted HTTP requests (CVE-2026-23864)
  • Apache ZooKeeper: Impersonation of servers or clients via reverse DNS spoofing (CVE-2026-24281)
  • netty-codec-http: Request smuggling via incorrect parsing of HTTP/1.1 chunked transfer encoding extension values (CVE-2026-33870)
  • netty-codec-http2: Denial of Service via HTTP/2 CONTINUATION frame flood (CVE-2026-33871)
  • log4j-core: Invalid XML output causes denial of service in logging (CVE-2026-34480)
  • quarkus-vertx-http: Authorization bypass via semicolons in HTTP requests (CVE-2026-39852)
  • netty-codec: Denial of Service via excessive memory allocation in LZ4FrameDecoder (CVE-2026-42583)
  • netty-codec-http2: Denial of Service via unbounded memory allocation in HTTP content decompression (CVE-2026-42587)
  • netty-handler: IPv6 subnet rule bypass due to incorrect masking operation (CVE-2026-44249)
  • Next.js: Information disclosure due to middleware bypass in Pages Router with i18n (CVE-2026-44573)
  • Next.js: Authorization bypass via crafted query parameters (CVE-2026-44574)
  • Next.js: Unauthorized access to protected content via middleware bypass (CVE-2026-44575)
  • Next.js: Server-Side Request Forgery via crafted WebSocket upgrade requests (CVE-2026-44578)
  • Next.js: Denial of Service via crafted POST requests to server actions (CVE-2026-44579)
  • netty-codec-haproxy: Denial of Service via malformed HAProxy message (CVE-2026-44893)
  • Next.js: Information disclosure via security fix bypass in middleware with Turbopack (CVE-2026-45109)
  • netty-handler: Denial of Service via eager buffer allocation in TLS handshake (CVE-2026-45416)
  • netty-resolver-dns: Information disclosure and data manipulation due to improper CNAME record validation (CVE-2026-45674)
  • netty-resolver-dns: Insufficient Bailiwick Validation for NS Records (CVE-2026-47691)
  • netty-codec-http2: Denial of Service due to resource leak (CVE-2026-48043)
  • netty-codec-haproxy: Denial of Service via memory leak from crafted PROXY protocol headers (CVE-2026-48059)
  • netty-handler: Improper trust manager handling leads to hostname verification bypass (CVE-2026-50010)
  • quarkus-vertx-http: Authorization bypass in HTTP path-based policies via encoded characters (CVE-2026-50559)
  • lodash: Prototype pollution in _.unset and _.omit functions (CVE-2025-13465)
  • vertx-core: Static handler component cache can be manipulated to deny access to static files (CVE-2026-1002)
  • vertx-core: Denial of Service via TLS handshake with wildcard server name (CVE-2026-6860)
  • Apache ZooKeeper: Information disclosure via improper handling of configuration values (CVE-2026-24308)
  • Next.js: Unbounded next/image disk cache growth can exhaust storage (CVE-2026-27980)
  • DOMPurify: Cross-Site Scripting (XSS) via inconsistent tag sanitization (CVE-2026-41240)
  • axios: Invisible JSON Response Tampering via Prototype Pollution Gadget (CVE-2026-42044)
  • Next.js: Denial of Service via Image Optimization API (CVE-2026-44577)

Solution

Before applying this update, make sure all previously released errata relevant to your system have been applied.

For details on how to apply this update, refer to:

https://access.redhat.com/articles/11258

Affected Products

ProductVersionArch
Red Hat JBoss Middleware1x86_64

Fixes

CVEs

References


Additional information