CVE-2018-1288: Apache Kafka

Medium severity, CVSS 5.4. EPSS: 4.8% chance of exploitation in the next 30 days.

In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.

Affected products

  • Apache Kafka: after 0.9.0.0, up to and including 0.9.0.1; from 0.10.0.0, up to and including 0.10.2.1; from 0.11.0.0, up to and including 0.11.0.2; version 1.0.0 only
  • Oracle Database: version 11.2.0.4 only; version 12.1.0.2 only; version 12.2.0.1 only; version 18c only; version 19c only
  • Oracle Primavera p6 Enterprise Project Portfolio Management: from 19.12.0.0, up to and including 19.12.6.0
  • Oracle Timesten In-Memory Database: before 18.1.2.1.0 (fixed in 18.1.2.1.0)
  • Red Hat JBoss Middleware Text-Only Advisories: version 1.0 only

Published 2018-07-26. Last modified 2026-06-17.