PT-2026-78828 · Splunk · Splunk Connect For Kafka
CVE-2026-76401
·
Published
2026-08-19
·
Updated
2026-08-19
CVSS v3.1
5.9
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Splunk Connect for Kafka versions prior to 2.2.7
Description
An unauthenticated user with access to the Kafka Connect Representational State Transfer (REST) API can cause a denial of service by configuring timestamp extraction using a crafted regular expression and matching event data. This action blocks a Kafka Connect worker thread, which stops event delivery for the affected connector. The issue occurs because the timestamp extraction process evaluates customer-supplied regular expressions without a time limit.
Recommendations
Update to version 2.2.7 or later.
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Splunk Connect For Kafka