{"id":"CVE-2026-10143","title":"kafka-python prior to 2.3.2 DoS via SCRAM Iteration Count in scram.py","summary":"kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the client event loop by supplying an excessively large iteration c…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"cna","cwe":["CWE-400","CWE-606"],"vendor":"Dana Powers","product":"kafka-python","affected":["kafka-python < 2.3.2"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-06-11T13:10:04.299411Z"},"published":"2026-06-10","updated":"2026-09-10","sourceUpdated":"2026-09-10T12:04:54.248Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2026-10143","references":[{"url":"https://github.com/dpkp/kafka-python/pull/3019"},{"url":"https://github.com/dpkp/kafka-python/commit/6e4831444f972d169cdd11f5c8d50333cea3f19b"},{"url":"https://github.com/dpkp/kafka-python/pull/3026"},{"url":"https://www.vulncheck.com/advisories/kafka-python-prior-to-dos-via-scram-iteration-count-in-scram-py"},{"url":"https://access.redhat.com/security/cve/CVE-2026-10143"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-10143.json"},{"url":"https://access.redhat.com/errata/RHSA-2026:28571"},{"url":"https://access.redhat.com/errata/RHSA-2026:30076"},{"url":"https://access.redhat.com/errata/RHSA-2026:33683"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2487722"},{"url":"https://github.com/advisories/GHSA-2jcm-hq8r-84wx"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-10143"},{"url":"https://github.com/dpkp/kafka-python/commit/74400d7ef1b54ad24d4b8170c23b58d1cab65e4f"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/kafka-python/PYSEC-2026-2191.yaml"},{"url":"https://github.com/dpkp/kafka-python/releases/tag/2.3.2"},{"url":"https://github.com/dpkp/kafka-python"},{"url":"https://access.redhat.com/errata/RHSA-2026:42796"},{"url":"https://access.redhat.com/errata/RHSA-2026:41066"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-10143"}],"tags":["cve.org","osv","pip","csaf","vex","red-hat","nvd"],"epss":0.00517,"epssPercentile":0.42825,"aliases":["PYSEC-2026-2191","GHSA-2jcm-hq8r-84wx"],"ecosystem":"pip","patched":["kafka-python 2.3.2"],"ingestedAt":"2026-07-13T18:58:07.955Z","slug":"CVE-2026-10143","body":"## Overview\n\nkafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the client event loop by supplying an excessively large iteration count. In scram.py, ScramClient.process_server_first_message() passes the broker-controlled SCRAM iteration count directly to hashlib.pbkdf2_hmac() without validation, blocking producer sends, consumer polls, admin operations, and heartbeats, which can cause consumer group eviction and repeated reconnect failures.\n\n## Affected\n\n- `kafka-python < 2.3.2`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-10143)\n\nAffected packages:\n\n- `kafka-python < 2.3.2`\n\nPatched in:\n\n- `kafka-python 2.3.2`\n\nSource: https://osv.dev/vulnerability/PYSEC-2026-2191\n\n## Vendor advisories\n\n- **RHSA-2026:33683** · Red Hat · fixed in: Red Hat Quay 3.10 · released 2026-06-30 · [advisory](https://access.redhat.com/errata/RHSA-2026:33683)\n- **RHSA-2026:30076** · Red Hat · fixed in: Red Hat Quay 3.12 · released 2026-06-25 · [advisory](https://access.redhat.com/errata/RHSA-2026:30076)\n- **RHSA-2026:42796** · Red Hat · fixed in: Red Hat Quay 3.15 · released 2026-07-21 · [advisory](https://access.redhat.com/errata/RHSA-2026:42796)\n- **RHSA-2026:41066** · Red Hat · fixed in: Red Hat Quay 3.16 · released 2026-07-16 · [advisory](https://access.redhat.com/errata/RHSA-2026:41066)\n- **RHSA-2026:28571** · Red Hat · fixed in: Red Hat Quay 3.9 · released 2026-06-23 · [advisory](https://access.redhat.com/errata/RHSA-2026:28571)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[{"seq":201439,"id":"CVE-2026-10143","ts":1789399449777,"field":"cvss","old":null,"new":"7.5"},{"seq":201438,"id":"CVE-2026-10143","ts":1789399449777,"field":"severity","old":"none","new":"high"},{"seq":200173,"id":"CVE-2026-10143","ts":1789396926792,"field":"cvss","old":"7.5","new":null},{"seq":200172,"id":"CVE-2026-10143","ts":1789396926792,"field":"severity","old":"high","new":"none"},{"seq":198094,"id":"CVE-2026-10143","ts":1789387950204,"field":"cvss","old":null,"new":"7.5"},{"seq":198093,"id":"CVE-2026-10143","ts":1789387950204,"field":"severity","old":"none","new":"high"},{"seq":195890,"id":"CVE-2026-10143","ts":1789383304809,"field":"cvss","old":"7.5","new":null},{"seq":195889,"id":"CVE-2026-10143","ts":1789383304809,"field":"severity","old":"high","new":"none"},{"seq":194819,"id":"CVE-2026-10143","ts":1789380272059,"field":"cvss","old":null,"new":"7.5"},{"seq":194818,"id":"CVE-2026-10143","ts":1789380272059,"field":"severity","old":"none","new":"high"},{"seq":193606,"id":"CVE-2026-10143","ts":1789378166953,"field":"cvss","old":"7.5","new":null},{"seq":193605,"id":"CVE-2026-10143","ts":1789378166953,"field":"severity","old":"high","new":"none"},{"seq":192393,"id":"CVE-2026-10143","ts":1789376190781,"field":"cvss","old":null,"new":"7.5"},{"seq":192392,"id":"CVE-2026-10143","ts":1789376190781,"field":"severity","old":"none","new":"high"},{"seq":191180,"id":"CVE-2026-10143","ts":1789373038756,"field":"cvss","old":"7.5","new":null},{"seq":191179,"id":"CVE-2026-10143","ts":1789373038756,"field":"severity","old":"high","new":"none"},{"seq":189965,"id":"CVE-2026-10143","ts":1789369093001,"field":"cvss","old":null,"new":"7.5"},{"seq":189964,"id":"CVE-2026-10143","ts":1789369093001,"field":"severity","old":"none","new":"high"},{"seq":188752,"id":"CVE-2026-10143","ts":1789367989425,"field":"cvss","old":"7.5","new":null},{"seq":188751,"id":"CVE-2026-10143","ts":1789367989425,"field":"severity","old":"high","new":"none"},{"seq":187535,"id":"CVE-2026-10143","ts":1789364941646,"field":"cvss","old":null,"new":"7.5"},{"seq":187534,"id":"CVE-2026-10143","ts":1789364941646,"field":"severity","old":"none","new":"high"},{"seq":186322,"id":"CVE-2026-10143","ts":1789362906412,"field":"cvss","old":"7.5","new":null},{"seq":186321,"id":"CVE-2026-10143","ts":1789362906412,"field":"severity","old":"high","new":"none"},{"seq":185108,"id":"CVE-2026-10143","ts":1789360928936,"field":"cvss","old":null,"new":"7.5"},{"seq":185107,"id":"CVE-2026-10143","ts":1789360928936,"field":"severity","old":"none","new":"high"},{"seq":183895,"id":"CVE-2026-10143","ts":1789357851006,"field":"cvss","old":"7.5","new":null},{"seq":183894,"id":"CVE-2026-10143","ts":1789357851006,"field":"severity","old":"high","new":"none"},{"seq":182147,"id":"CVE-2026-10143","ts":1789354054593,"field":"cvss","old":null,"new":"7.5"},{"seq":182146,"id":"CVE-2026-10143","ts":1789354054593,"field":"severity","old":"none","new":"high"},{"seq":180940,"id":"CVE-2026-10143","ts":1789352878495,"field":"cvss","old":"7.5","new":null},{"seq":180939,"id":"CVE-2026-10143","ts":1789352878495,"field":"severity","old":"high","new":"none"},{"seq":179733,"id":"CVE-2026-10143","ts":1789349951497,"field":"cvss","old":null,"new":"7.5"},{"seq":179732,"id":"CVE-2026-10143","ts":1789349951497,"field":"severity","old":"none","new":"high"},{"seq":178526,"id":"CVE-2026-10143","ts":1789347713606,"field":"cvss","old":"7.5","new":null},{"seq":178525,"id":"CVE-2026-10143","ts":1789347713606,"field":"severity","old":"high","new":"none"},{"seq":177319,"id":"CVE-2026-10143","ts":1789346134190,"field":"cvss","old":null,"new":"7.5"},{"seq":177318,"id":"CVE-2026-10143","ts":1789346134190,"field":"severity","old":"none","new":"high"},{"seq":176112,"id":"CVE-2026-10143","ts":1789342648292,"field":"cvss","old":"7.5","new":null},{"seq":176111,"id":"CVE-2026-10143","ts":1789342648292,"field":"severity","old":"high","new":"none"},{"seq":175898,"id":"CVE-2026-10143","ts":1789342261700,"field":"cvss","old":null,"new":"7.5"},{"seq":175897,"id":"CVE-2026-10143","ts":1789342261700,"field":"severity","old":"none","new":"high"},{"seq":175436,"id":"CVE-2026-10143","ts":1789338286278,"field":"cvss","old":"7.5","new":null},{"seq":175435,"id":"CVE-2026-10143","ts":1789338286278,"field":"severity","old":"high","new":"none"},{"seq":174231,"id":"CVE-2026-10143","ts":1789334561218,"field":"cvss","old":null,"new":"7.5"},{"seq":174230,"id":"CVE-2026-10143","ts":1789334561218,"field":"severity","old":"none","new":"high"},{"seq":173026,"id":"CVE-2026-10143","ts":1789333123284,"field":"cvss","old":"7.5","new":null},{"seq":173025,"id":"CVE-2026-10143","ts":1789333123284,"field":"severity","old":"high","new":"none"},{"seq":171840,"id":"CVE-2026-10143","ts":1789330837699,"field":"cvss","old":null,"new":"7.5"},{"seq":171839,"id":"CVE-2026-10143","ts":1789330837699,"field":"severity","old":"none","new":"high"}]}